Malware problem

  1. #1
    qili26 is offline Junior Member

    Malware problem

    I was on this website for my research and all of a sudden I started getting fake alerts to buy security protection products. Unfortuately the first time it popped up, I didn't realize this is a spyware/malware and I clicked "remove all" thinking I was removing these issues. I then ran SuperAntiSpyware to try to get rid off all the pop up screens. Their scan showed that they found Trojan.Agent/Gen-FakeAlert and BrowserHijakcer.Internet Explorer Settings Hijack. SuperAntiSpyware seemed to get rid of the popup windows but I want to make sure that my registry is clean and everything else is removed as well. How do I proceed?

    In the past, Broni walked me through all the steps for another issue and was really helpful to me. I hope to get rid off everything with your help this time. Thank you!

  2. #2
    broni is offline Senior Member
    Welcome aboard

    Please, complete all steps listed here: HERE

    Please, observe following rules:
    • Read all of my instructions very carefully. Your mistakes during cleaning process may have very serious consequences, like unbootable computer.
    • If you're stuck, or you're not sure about certain step, always ask before doing anything else.
    • Please refrain from running tools or applying updates other than those I suggest.
    • Never run more than one scan at a time.
    • Keep updating me regarding your computer behavior, good, or bad.
    • The cleaning process, once started, has to be completed. Even if your computer appears to act better, it may still be infected. Once the computer is totally clean, I'll certainly let you know.
    • If you leave the topic without explanation in the middle of a cleaning process, you may not be eligible to receive any more help in malware removal forum.
    • I close my topics if you have not replied in 5 days. If you need more time, simply let me know. If I closed your topic and you need it to be reopened, simply PM me.

  3. #3
    qili26 is offline Junior Member
    Broni,

    Thank you for your reply. I downloaded Avira, which displayed this message when I restarted my computer "the access to autorun.inf" was blocked.

    Since I downloaded Malware last time, I updated it instead of redownloading the whole thing. I ran the .exe file you mentioned. It asked me to restart the computer so I did. But I didn't see the part where it asked me to "checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware," but I did see the application file to run from last time. So although it did not launch automatically after I ran the .exe file, I clicked on that icon and saw the screen you were referring to to perform the quick scan. Is this ok? Or should I go ahead and delete the old Malware and then reinstall it like it was the first time. Anyway, if what I did was okay, here is the log results:


    From Malware:

    Malwarebytes' Anti-Malware 1.51.0.1200
    Malwarebytes : Free anti-malware, anti-virus and spyware removal download

    Database version: 6705

    Windows 6.0.6002 Service Pack 2
    Internet Explorer 8.0.6001.19048

    6/4/2011 12:07:52 PM
    mbam-log-2011-06-04 (12-07-52).txt

    Scan type: Quick scan
    Objects scanned: 170905
    Time elapsed: 8 minute(s), 26 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 0
    Registry Values Infected: 0
    Registry Data Items Infected: 1
    Folders Infected: 1
    Files Infected: 2

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    (No malicious items detected)

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    HKEY_CLASSES_ROOT\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\URL (Hijack.SearchPage) -> Bad: (http://findgala.com/?&uid=2194&q={searchTerms}) Good: (http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language }&ie={inputEncoding}&oe={outputEncoding}&startInde x={startIndex?}&startPage={startPage}) -> Quarantined and deleted successfully.

    Folders Infected:
    c:\Users\lqi\AppData\Roaming\pc security guardian (Rogue.PCSecurityGuardian) -> Quarantined and deleted successfully.

    Files Infected:
    c:\Users\lqi\AppData\Roaming\pc security guardian\instructions.ini (Rogue.PCSecurityGuardian) -> Quarantined and deleted successfully.
    c:\Users\lqi\AppData\Roaming\pc security guardian\cookies.sqlite (Rogue.PCSecurityGuardian) -> Quarantined and deleted successfully.



    From gmer:

    GMER 1.0.15.15640 - GMER - Rootkit Detector and Remover
    Rootkit scan 2011-06-04 13:42:39
    Windows 6.0.6002 Service Pack 2
    Running: 20zu1ehy.exe


    ---- Files - GMER 1.0.15 ----

    File C:\RRbackups\C 0 bytes
    File C:\RRbackups\C\0 0 bytes
    File C:\RRbackups\C\0\Data479 50003968 bytes
    File C:\RRbackups\C\0\Data0 50003968 bytes
    File C:\RRbackups\C\0\Data1 50003968 bytes
    File C:\RRbackups\C\0\Data10 50003968 bytes
    File C:\RRbackups\C\0\Data100 50003968 bytes
    File C:\RRbackups\C\0\Data1000 50003968 bytes
    File C:\RRbackups\C\0\Data1001 50003968 bytes
    File C:\RRbackups\C\0\Data1002 50003968 bytes
    File C:\RRbackups\C\0\Data1003 50003968 bytes
    File C:\RRbackups\C\0\Data1004 50003968 bytes
    File C:\RRbackups\C\0\Data1005 50003968 bytes
    File C:\RRbackups\C\0\Data1006 50003968 bytes
    File C:\RRbackups\C\0\Data1007 50003968 bytes
    File C:\RRbackups\C\0\Data1008 50003968 bytes
    File C:\RRbackups\C\0\Data1009 50003968 bytes
    File C:\RRbackups\C\0\Data101 50003968 bytes
    File C:\RRbackups\C\0\Data1010 50003968 bytes
    File C:\RRbackups\C\0\Data1011 50003968 bytes
    File C:\RRbackups\C\0\Data1012 50003968 bytes
    File C:\RRbackups\C\0\Data1013 50003968 bytes
    File C:\RRbackups\C\0\Data1014 50003968 bytes
    File C:\RRbackups\C\0\Data1015 50003968 bytes
    File C:\RRbackups\C\0\Data1016 47697952 bytes
    File C:\RRbackups\C\0\Data102 50003968 bytes
    File C:\RRbackups\C\0\Data103 50003968 bytes
    File C:\RRbackups\C\0\Data104 50003968 bytes
    File C:\RRbackups\C\0\Data105 50003968 bytes
    File C:\RRbackups\C\0\Data106 50003968 bytes
    File C:\RRbackups\C\0\Data107 50003968 bytes
    File C:\RRbackups\C\0\Data108 50003968 bytes
    File C:\RRbackups\C\0\Data109 50003968 bytes
    File C:\RRbackups\C\0\Data11 50003968 bytes
    File C:\RRbackups\C\0\Data110 50003968 bytes
    File C:\RRbackups\C\0\Data111 50003968 bytes
    File C:\RRbackups\C\0\Data112 50003968 bytes
    File C:\RRbackups\C\0\Data113 50003968 bytes
    File C:\RRbackups\C\0\Data114 50003968 bytes
    File C:\RRbackups\C\0\Data115 50003968 bytes
    File C:\RRbackups\C\0\Data270 50003968 bytes
    File C:\RRbackups\C\0\Data271 50003968 bytes
    File C:\RRbackups\C\0\Data272 50003968 bytes
    File C:\RRbackups\C\0\Data273 50003968 bytes
    File C:\RRbackups\C\0\Data274 50003968 bytes
    File C:\RRbackups\C\0\Data275 50003968 bytes
    File C:\RRbackups\C\0\Data276 50003968 bytes
    File C:\RRbackups\C\0\Data277 50003968 bytes
    File C:\RRbackups\C\0\Data278 50003968 bytes
    File C:\RRbackups\C\0\Data279 50003968 bytes
    File C:\RRbackups\C\0\Data28 50003968 bytes
    File C:\RRbackups\C\0\Data280 50003968 bytes
    File C:\RRbackups\C\0\Data281 50003968 bytes
    File C:\RRbackups\C\0\Data282 50003968 bytes
    File C:\RRbackups\C\0\Data283 50003968 bytes
    File C:\RRbackups\C\0\Data284 50003968 bytes
    File C:\RRbackups\C\0\Data285 50003968 bytes
    File C:\RRbackups\C\0\Data286 50003968 bytes
    File C:\RRbackups\C\0\Data287 50003968 bytes
    File C:\RRbackups\C\0\Data288 50003968 bytes
    File C:\RRbackups\C\0\Data460 50003968 bytes
    File C:\RRbackups\C\0\Data461 50003968 bytes
    File C:\RRbackups\C\0\Data462 50003968 bytes
    File C:\RRbackups\C\0\Data463 50003968 bytes
    File C:\RRbackups\C\0\Data464 50003968 bytes
    File C:\RRbackups\C\0\Data465 50003968 bytes
    File C:\RRbackups\C\0\Data466 50003968 bytes
    File C:\RRbackups\C\0\Data467 50003968 bytes
    File C:\RRbackups\C\0\Data468 50003968 bytes
    File C:\RRbackups\C\0\Data469 50003968 bytes
    File C:\RRbackups\C\0\Data47 50003968 bytes
    File C:\RRbackups\C\0\Data470 50003968 bytes
    File C:\RRbackups\C\0\Data471 50003968 bytes
    File C:\RRbackups\C\0\Data472 50003968 bytes
    File C:\RRbackups\C\0\Data473 50003968 bytes
    File C:\RRbackups\C\0\Data474 50003968 bytes
    File C:\RRbackups\C\0\Data475 50003968 bytes
    File C:\RRbackups\C\0\Data476 50003968 bytes
    File C:\RRbackups\C\0\Data477 50003968 bytes
    File C:\RRbackups\C\0\Data478 50003968 bytes
    File C:\RRbackups\C\0\Data650 50003968 bytes
    File C:\RRbackups\C\0\Data651 50003968 bytes
    File C:\RRbackups\C\0\Data652 50003968 bytes
    File C:\RRbackups\C\0\Data653 50003968 bytes
    File C:\RRbackups\C\0\Data654 50003968 bytes
    File C:\RRbackups\C\0\Data655 50003968 bytes
    File C:\RRbackups\C\0\Data656 50003968 bytes
    File C:\RRbackups\C\0\Data657 50003968 bytes
    File C:\RRbackups\C\0\Data658 50003968 bytes
    File C:\RRbackups\C\0\Data659 50003968 bytes
    File C:\RRbackups\C\0\Data66 50003968 bytes
    File C:\RRbackups\C\0\Data660 50003968 bytes
    File C:\RRbackups\C\0\Data661 50003968 bytes
    File C:\RRbackups\C\0\Data662 50003968 bytes
    File C:\RRbackups\C\0\Data663 50003968 bytes
    File C:\RRbackups\C\0\Data664 50003968 bytes
    File C:\RRbackups\C\0\Data665 50003968 bytes
    File C:\RRbackups\C\0\Data666 50003968 bytes
    File C:\RRbackups\C\0\Data667 50003968 bytes
    File C:\RRbackups\C\0\Data668 50003968 bytes
    File C:\RRbackups\C\0\Data117 50003968 bytes
    File C:\RRbackups\C\0\Data118 50003968 bytes
    File C:\RRbackups\C\0\Data119 50003968 bytes
    File C:\RRbackups\C\0\Data12 50003968 bytes
    File C:\RRbackups\C\0\Data120 50003968 bytes
    File C:\RRbackups\C\0\Data121 50003968 bytes
    File C:\RRbackups\C\0\Data122 50003968 bytes
    File C:\RRbackups\C\0\Data123 50003968 bytes
    File C:\RRbackups\C\0\Data124 50003968 bytes
    File C:\RRbackups\C\0\Data125 50003968 bytes
    File C:\RRbackups\C\0\Data126 50003968 bytes
    File C:\RRbackups\C\0\Data127 50003968 bytes
    File C:\RRbackups\C\0\Data128 50003968 bytes
    File C:\RRbackups\C\0\Data129 50003968 bytes
    File C:\RRbackups\C\0\Data13 50003968 bytes
    File C:\RRbackups\C\0\Data130 50003968 bytes
    File C:\RRbackups\C\0\Data131 50003968 bytes
    File C:\RRbackups\C\0\Data132 50003968 bytes
    File C:\RRbackups\C\0\Data133 50003968 bytes
    File C:\RRbackups\C\0\Data134 50003968 bytes
    File C:\RRbackups\C\0\Data136 50003968 bytes
    File C:\RRbackups\C\0\Data137 50003968 bytes
    File C:\RRbackups\C\0\Data138 50003968 bytes
    File C:\RRbackups\C\0\Data139 50003968 bytes
    File C:\RRbackups\C\0\Data14 50003968 bytes
    File C:\RRbackups\C\0\Data140 50003968 bytes
    File C:\RRbackups\C\0\Data141 50003968 bytes
    File C:\RRbackups\C\0\Data142 50003968 bytes
    File C:\RRbackups\C\0\Data143 50003968 bytes
    File C:\RRbackups\C\0\Data144 50003968 bytes
    File C:\RRbackups\C\0\Data145 50003968 bytes
    File C:\RRbackups\C\0\Data146 50003968 bytes
    File C:\RRbackups\C\0\Data147 50003968 bytes
    File C:\RRbackups\C\0\Data148 50003968 bytes
    File C:\RRbackups\C\0\Data149 50003968 bytes
    File C:\RRbackups\C\0\Data15 50003968 bytes
    File C:\RRbackups\C\0\Data150 50003968 bytes
    File C:\RRbackups\C\0\Data151 50003968 bytes
    File C:\RRbackups\C\0\Data152 50003968 bytes
    File C:\RRbackups\C\0\Data153 50003968 bytes
    File C:\RRbackups\C\0\Data155 50003968 bytes
    File C:\RRbackups\C\0\Data156 50003968 bytes
    File C:\RRbackups\C\0\Data157 50003968 bytes
    File C:\RRbackups\C\0\Data158 50003968 bytes
    File C:\RRbackups\C\0\Data159 50003968 bytes
    File C:\RRbackups\C\0\Data16 50003968 bytes
    File C:\RRbackups\C\0\Data160 50003968 bytes
    File C:\RRbackups\C\0\Data161 50003968 bytes
    File C:\RRbackups\C\0\Data162 50003968 bytes
    File C:\RRbackups\C\0\Data163 50003968 bytes
    File C:\RRbackups\C\0\Data164 50003968 bytes
    File C:\RRbackups\C\0\Data165 50003968 bytes
    File C:\RRbackups\C\0\Data166 50003968 bytes
    File C:\RRbackups\C\0\Data167 50003968 bytes
    File C:\RRbackups\C\0\Data168 50003968 bytes
    File C:\RRbackups\C\0\Data169 50003968 bytes
    File C:\RRbackups\C\0\Data17 50003968 bytes
    File C:\RRbackups\C\0\Data170 50003968 bytes
    File C:\RRbackups\C\0\Data171 50003968 bytes
    File C:\RRbackups\C\0\Data172 50003968 bytes
    File C:\RRbackups\C\0\Data116 50003968 bytes
    File C:\RRbackups\C\0\Data135 50003968 bytes
    File C:\RRbackups\C\0\Data154 50003968 bytes
    File C:\RRbackups\C\0\Data173 50003968 bytes
    File C:\RRbackups\C\0\Data192 50003968 bytes
    File C:\RRbackups\C\0\Data210 50003968 bytes
    File C:\RRbackups\C\0\Data23 50003968 bytes
    File C:\RRbackups\C\0\Data249 50003968 bytes
    File C:\RRbackups\C\0\Data27 50003968 bytes
    File C:\RRbackups\C\0\Data289 50003968 bytes
    File C:\RRbackups\C\0\Data307 50003968 bytes
    File C:\RRbackups\C\0\Data326 50003968 bytes
    File C:\RRbackups\C\0\Data345 50003968 bytes
    File C:\RRbackups\C\0\Data364 50003968 bytes
    File C:\RRbackups\C\0\Data383 50003968 bytes
    File C:\RRbackups\C\0\Data401 50003968 bytes
    File C:\RRbackups\C\0\Data420 50003968 bytes
    File C:\RRbackups\C\0\Data44 50003968 bytes
    File C:\RRbackups\C\0\Data46 50003968 bytes
    File C:\RRbackups\C\0\Data174 50003968 bytes
    File C:\RRbackups\C\0\Data175 50003968 bytes
    File C:\RRbackups\C\0\Data176 50003968 bytes
    File C:\RRbackups\C\0\Data177 50003968 bytes
    File C:\RRbackups\C\0\Data178 50003968 bytes
    File C:\RRbackups\C\0\Data179 50003968 bytes
    File C:\RRbackups\C\0\Data18 50003968 bytes
    File C:\RRbackups\C\0\Data180 50003968 bytes
    File C:\RRbackups\C\0\Data181 50003968 bytes
    File C:\RRbackups\C\0\Data182 50003968 bytes
    File C:\RRbackups\C\0\Data183 50003968 bytes
    File C:\RRbackups\C\0\Data184 50003968 bytes
    File C:\RRbackups\C\0\Data185 50003968 bytes
    File C:\RRbackups\C\0\Data186 50003968 bytes
    File C:\RRbackups\C\0\Data187 50003968 bytes
    File C:\RRbackups\C\0\Data188 50003968 bytes
    File C:\RRbackups\C\0\Data189 50003968 bytes
    File C:\RRbackups\C\0\Data19 50003968 bytes
    File C:\RRbackups\C\0\Data190 50003968 bytes
    File C:\RRbackups\C\0\Data191 50003968 bytes
    File C:\RRbackups\C\0\Data193 50003968 bytes
    File C:\RRbackups\C\0\Data194 50003968 bytes
    File C:\RRbackups\C\0\Data195 50003968 bytes
    File C:\RRbackups\C\0\Data196 50003968 bytes
    File C:\RRbackups\C\0\Data197 50003968 bytes
    File C:\RRbackups\C\0\Data198 50003968 bytes
    File C:\RRbackups\C\0\Data199 50003968 bytes
    File C:\RRbackups\C\0\Data2 50003968 bytes
    File C:\RRbackups\C\0\Data20 50003968 bytes
    File C:\RRbackups\C\0\Data200 50003968 bytes
    File C:\RRbackups\C\0\Data201 50003968 bytes
    File C:\RRbackups\C\0\Data202 50003968 bytes
    File C:\RRbackups\C\0\Data203 50003968 bytes
    File C:\RRbackups\C\0\Data204 50003968 bytes
    File C:\RRbackups\C\0\Data205 50003968 bytes
    File C:\RRbackups\C\0\Data206 50003968 bytes
    File C:\RRbackups\C\0\Data207 50003968 bytes
    File C:\RRbackups\C\0\Data208 50003968 bytes
    File C:\RRbackups\C\0\Data209 50003968 bytes
    File C:\RRbackups\C\0\Data21 50003968 bytes
    File C:\RRbackups\C\0\Data211 50003968 bytes
    File C:\RRbackups\C\0\Data212 50003968 bytes
    File C:\RRbackups\C\0\Data213 50003968 bytes
    File C:\RRbackups\C\0\Data214 50003968 bytes
    File C:\RRbackups\C\0\Data215 50003968 bytes
    File C:\RRbackups\C\0\Data216 50003968 bytes
    File C:\RRbackups\C\0\Data217 50003968 bytes
    File C:\RRbackups\C\0\Data218 50003968 bytes
    File C:\RRbackups\C\0\Data219 50003968 bytes
    File C:\RRbackups\C\0\Data22 50003968 bytes
    File C:\RRbackups\C\0\Data220 50003968 bytes
    File C:\RRbackups\C\0\Data221 50003968 bytes
    File C:\RRbackups\C\0\Data222 50003968 bytes
    File C:\RRbackups\C\0\Data223 50003968 bytes
    File C:\RRbackups\C\0\Data224 50003968 bytes
    File C:\RRbackups\C\0\Data225 50003968 bytes
    File C:\RRbackups\C\0\Data226 50003968 bytes
    File C:\RRbackups\C\0\Data227 50003968 bytes
    File C:\RRbackups\C\0\Data228 50003968 bytes
    File C:\RRbackups\C\0\Data229 50003968 bytes
    File C:\RRbackups\C\0\Data230 50003968 bytes
    File C:\RRbackups\C\0\Data231 50003968 bytes
    File C:\RRbackups\C\0\Data232 50003968 bytes
    File C:\RRbackups\C\0\Data233 50003968 bytes
    File C:\RRbackups\C\0\Data234 50003968 bytes
    File C:\RRbackups\C\0\Data235 50003968 bytes
    File C:\RRbackups\C\0\Data236 50003968 bytes
    File C:\RRbackups\C\0\Data237 50003968 bytes
    File C:\RRbackups\C\0\Data238 50003968 bytes
    File C:\RRbackups\C\0\Data239 50003968 bytes
    File C:\RRbackups\C\0\Data24 50003968 bytes
    File C:\RRbackups\C\0\Data240 50003968 bytes
    File C:\RRbackups\C\0\Data241 50003968 bytes
    File C:\RRbackups\C\0\Data242 50003968 bytes
    File C:\RRbackups\C\0\Data243 50003968 bytes
    File C:\RRbackups\C\0\Data244 50003968 bytes
    File C:\RRbackups\C\0\Data245 50003968 bytes
    File C:\RRbackups\C\0\Data246 50003968 bytes
    File C:\RRbackups\C\0\Data247 50003968 bytes
    File C:\RRbackups\C\0\Data248 50003968 bytes
    File C:\RRbackups\C\0\Data25 50003968 bytes
    File C:\RRbackups\C\0\Data250 50003968 bytes
    File C:\RRbackups\C\0\Data251 50003968 bytes
    File C:\RRbackups\C\0\Data252 50003968 bytes
    File C:\RRbackups\C\0\Data253 50003968 bytes
    File C:\RRbackups\C\0\Data254 50003968 bytes
    File C:\RRbackups\C\0\Data255 50003968 bytes
    File C:\RRbackups\C\0\Data256 50003968 bytes
    File C:\RRbackups\C\0\Data257 50003968 bytes
    File C:\RRbackups\C\0\Data258 50003968 bytes
    File C:\RRbackups\C\0\Data259 50003968 bytes
    File C:\RRbackups\C\0\Data26 50003968 bytes
    File C:\RRbackups\C\0\Data260 50003968 bytes
    File C:\RRbackups\C\0\Data261 50003968 bytes
    File C:\RRbackups\C\0\Data262 50003968 bytes
    File C:\RRbackups\C\0\Data263 50003968 bytes
    File C:\RRbackups\C\0\Data264 50003968 bytes
    File C:\RRbackups\C\0\Data265 50003968 bytes
    File C:\RRbackups\C\0\Data266 50003968 bytes
    File C:\RRbackups\C\0\Data267 50003968 bytes
    File C:\RRbackups\C\0\Data268 50003968 bytes
    File C:\RRbackups\C\0\Data269 50003968 bytes
    File C:\RRbackups\C\0\Data29 50003968 bytes
    File C:\RRbackups\C\0\Data290 50003968 bytes
    File C:\RRbackups\C\0\Data291 50003968 bytes
    File C:\RRbackups\C\0\Data292 50003968 bytes
    File C:\RRbackups\C\0\Data293 50003968 bytes
    File C:\RRbackups\C\0\Data294 50003968 bytes
    File C:\RRbackups\C\0\Data295 50003968 bytes
    File C:\RRbackups\C\0\Data296 50003968 bytes
    File C:\RRbackups\C\0\Data297 50003968 bytes
    File C:\RRbackups\C\0\Data298 50003968 bytes
    File C:\RRbackups\C\0\Data299 50003968 bytes
    File C:\RRbackups\C\0\Data3 50003968 bytes
    File C:\RRbackups\C\0\Data30 50003968 bytes
    File C:\RRbackups\C\0\Data300 50003968 bytes
    File C:\RRbackups\C\0\Data301 50003968 bytes
    File C:\RRbackups\C\0\Data302 50003968 bytes
    File C:\RRbackups\C\0\Data303 50003968 bytes
    File C:\RRbackups\C\0\Data304 50003968 bytes
    File C:\RRbackups\C\0\Data305 50003968 bytes
    File C:\RRbackups\C\0\Data306 50003968 bytes
    File C:\RRbackups\C\0\Data308 50003968 bytes
    File C:\RRbackups\C\0\Data309 50003968 bytes
    File C:\RRbackups\C\0\Data31 50003968 bytes
    File C:\RRbackups\C\0\Data310 50003968 bytes
    File C:\RRbackups\C\0\Data311 50003968 bytes
    File C:\RRbackups\C\0\Data312 50003968 bytes
    File C:\RRbackups\C\0\Data313 50003968 bytes
    File C:\RRbackups\C\0\Data314 50003968 bytes
    File C:\RRbackups\C\0\Data315 50003968 bytes
    File C:\RRbackups\C\0\Data316 50003968 bytes
    File C:\RRbackups\C\0\Data317 50003968 bytes
    File C:\RRbackups\C\0\Data318 50003968 bytes
    File C:\RRbackups\C\0\Data319 50003968 bytes
    File C:\RRbackups\C\0\Data32 50003968 bytes
    File C:\RRbackups\C\0\Data320 50003968 bytes
    File C:\RRbackups\C\0\Data321 50003968 bytes
    File C:\RRbackups\C\0\Data322 50003968 bytes
    File C:\RRbackups\C\0\Data323 50003968 bytes
    File C:\RRbackups\C\0\Data324 50003968 bytes
    File C:\RRbackups\C\0\Data325 50003968 bytes
    File C:\RRbackups\C\0\Data327 50003968 bytes
    File C:\RRbackups\C\0\Data328 50003968 bytes
    File C:\RRbackups\C\0\Data329 50003968 bytes
    File C:\RRbackups\C\0\Data33 50003968 bytes
    File C:\RRbackups\C\0\Data330 50003968 bytes
    File C:\RRbackups\C\0\Data331 50003968 bytes
    File C:\RRbackups\C\0\Data332 50003968 bytes
    File C:\RRbackups\C\0\Data333 50003968 bytes
    File C:\RRbackups\C\0\Data334 50003968 bytes
    File C:\RRbackups\C\0\Data335 50003968 bytes
    File C:\RRbackups\C\0\Data336 50003968 bytes
    File C:\RRbackups\C\0\Data337 50003968 bytes
    File C:\RRbackups\C\0\Data338 50003968 bytes
    File C:\RRbackups\C\0\Data339 50003968 bytes
    File C:\RRbackups\C\0\Data34 50003968 bytes
    File C:\RRbackups\C\0\Data340 50003968 bytes
    File C:\RRbackups\C\0\Data341 50003968 bytes
    File C:\RRbackups\C\0\Data342 50003968 bytes
    File C:\RRbackups\C\0\Data343 50003968 bytes
    File C:\RRbackups\C\0\Data344 50003968 bytes
    File C:\RRbackups\C\0\Data346 50003968 bytes
    File C:\RRbackups\C\0\Data347 50003968 bytes
    File C:\RRbackups\C\0\Data348 50003968 bytes
    File C:\RRbackups\C\0\Data349 50003968 bytes
    File C:\RRbackups\C\0\Data35 50003968 bytes
    File C:\RRbackups\C\0\Data350 50003968 bytes
    File C:\RRbackups\C\0\Data351 50003968 bytes
    File C:\RRbackups\C\0\Data352 50003968 bytes
    File C:\RRbackups\C\0\Data353 50003968 bytes
    File C:\RRbackups\C\0\Data354 50003968 bytes
    File C:\RRbackups\C\0\Data355 50003968 bytes
    File C:\RRbackups\C\0\Data356 50003968 bytes
    File C:\RRbackups\C\0\Data357 50003968 bytes
    File C:\RRbackups\C\0\Data358 50003968 bytes
    File C:\RRbackups\C\0\Data359 50003968 bytes
    File C:\RRbackups\C\0\Data36 50003968 bytes
    File C:\RRbackups\C\0\Data360 50003968 bytes
    File C:\RRbackups\C\0\Data361 50003968 bytes
    File C:\RRbackups\C\0\Data362 50003968 bytes
    File C:\RRbackups\C\0\Data363 50003968 bytes
    File C:\RRbackups\C\0\Data365 50003968 bytes
    File C:\RRbackups\C\0\Data366 50003968 bytes
    File C:\RRbackups\C\0\Data367 50003968 bytes
    File C:\RRbackups\C\0\Data368 50003968 bytes
    File C:\RRbackups\C\0\Data369 50003968 bytes
    File C:\RRbackups\C\0\Data37 50003968 bytes
    File C:\RRbackups\C\0\Data370 50003968 bytes
    File C:\RRbackups\C\0\Data371 50003968 bytes
    File C:\RRbackups\C\0\Data372 50003968 bytes
    File C:\RRbackups\C\0\Data373 50003968 bytes
    File C:\RRbackups\C\0\Data374 50003968 bytes
    File C:\RRbackups\C\0\Data375 50003968 bytes
    File C:\RRbackups\C\0\Data376 50003968 bytes
    File C:\RRbackups\C\0\Data377 50003968 bytes
    File C:\RRbackups\C\0\Data378 50003968 bytes
    File C:\RRbackups\C\0\Data379 50003968 bytes
    File C:\RRbackups\C\0\Data38 50003968 bytes
    File C:\RRbackups\C\0\Data380 50003968 bytes
    File C:\RRbackups\C\0\Data381 50003968 bytes
    File C:\RRbackups\C\0\Data382 50003968 bytes
    File C:\RRbackups\C\0\Data384 50003968 bytes
    File C:\RRbackups\C\0\Data385 50003968 bytes
    File C:\RRbackups\C\0\Data386 50003968 bytes
    File C:\RRbackups\C\0\Data387 50003968 bytes
    File C:\RRbackups\C\0\Data388 50003968 bytes
    File C:\RRbackups\C\0\Data389 50003968 bytes
    File C:\RRbackups\C\0\Data39 50003968 bytes
    File C:\RRbackups\C\0\Data390 50003968 bytes
    File C:\RRbackups\C\0\Data391 50003968 bytes
    File C:\RRbackups\C\0\Data392 50003968 bytes
    File C:\RRbackups\C\0\Data393 50003968 bytes
    File C:\RRbackups\C\0\Data394 50003968 bytes
    File C:\RRbackups\C\0\Data395 50003968 bytes
    File C:\RRbackups\C\0\Data396 50003968 bytes
    File C:\RRbackups\C\0\Data397 50003968 bytes
    File C:\RRbackups\C\0\Data398 50003968 bytes
    File C:\RRbackups\C\0\Data399 50003968 bytes
    File C:\RRbackups\C\0\Data4 50003968 bytes
    File C:\RRbackups\C\0\Data40 50003968 bytes
    File C:\RRbackups\C\0\Data400 50003968 bytes
    File C:\RRbackups\C\0\Data402 50003968 bytes
    File C:\RRbackups\C\0\Data403 50003968 bytes
    File C:\RRbackups\C\0\Data404 50003968 bytes
    File C:\RRbackups\C\0\Data405 50003968 bytes
    File C:\RRbackups\C\0\Data406 50003968 bytes
    File C:\RRbackups\C\0\Data407 50003968 bytes
    File C:\RRbackups\C\0\Data408 50003968 bytes
    File C:\RRbackups\C\0\Data409 50003968 bytes
    File C:\RRbackups\C\0\Data41 50003968 bytes
    File C:\RRbackups\C\0\Data410 50003968 bytes
    File C:\RRbackups\C\0\Data411 50003968 bytes
    File C:\RRbackups\C\0\Data412 50003968 bytes
    File C:\RRbackups\C\0\Data413 50003968 bytes
    File C:\RRbackups\C\0\Data414 50003968 bytes
    File C:\RRbackups\C\0\Data415 50003968 bytes
    File C:\RRbackups\C\0\Data416 50003968 bytes
    File C:\RRbackups\C\0\Data417 50003968 bytes
    File C:\RRbackups\C\0\Data418 50003968 bytes
    File C:\RRbackups\C\0\Data419 50003968 bytes
    File C:\RRbackups\C\0\Data42 50003968 bytes
    File C:\RRbackups\C\0\Data421 50003968 bytes
    File C:\RRbackups\C\0\Data422 50003968 bytes
    File C:\RRbackups\C\0\Data423 50003968 bytes
    File C:\RRbackups\C\0\Data424 50003968 bytes
    File C:\RRbackups\C\0\Data425 50003968 bytes
    File C:\RRbackups\C\0\Data426 50003968 bytes
    File C:\RRbackups\C\0\Data427 50003968 bytes
    File C:\RRbackups\C\0\Data428 50003968 bytes
    File C:\RRbackups\C\0\Data429 50003968 bytes
    File C:\RRbackups\C\0\Data43 50003968 bytes
    File C:\RRbackups\C\0\Data430 50003968 bytes
    File C:\RRbackups\C\0\Data431 50003968 bytes
    File C:\RRbackups\C\0\Data432 50003968 bytes
    File C:\RRbackups\C\0\Data433 50003968 bytes
    File C:\RRbackups\C\0\Data434 50003968 bytes
    File C:\RRbackups\C\0\Data435 50003968 bytes
    File C:\RRbackups\C\0\Data436 50003968 bytes
    File C:\RRbackups\C\0\Data437 50003968 bytes
    File C:\RRbackups\C\0\Data438 50003968 bytes
    File C:\RRbackups\C\0\Data439 50003968 bytes
    File C:\RRbackups\C\0\Data440 50003968 bytes
    File C:\RRbackups\C\0\Data441 50003968 bytes
    File C:\RRbackups\C\0\Data442 50003968 bytes
    File C:\RRbackups\C\0\Data443 50003968 bytes
    File C:\RRbackups\C\0\Data444 50003968 bytes
    File C:\RRbackups\C\0\Data445 50003968 bytes
    File C:\RRbackups\C\0\Data446 50003968 bytes
    File C:\RRbackups\C\0\Data447 50003968 bytes
    File C:\RRbackups\C\0\Data448 50003968 bytes
    File C:\RRbackups\C\0\Data449 50003968 bytes
    File C:\RRbackups\C\0\Data45 50003968 bytes
    File C:\RRbackups\C\0\Data450 50003968 bytes
    File C:\RRbackups\C\0\Data451 50003968 bytes
    File C:\RRbackups\C\0\Data452 50003968 bytes
    File C:\RRbackups\C\0\Data453 50003968 bytes
    File C:\RRbackups\C\0\Data454 50003968 bytes
    File C:\RRbackups\C\0\Data455 50003968 bytes
    File C:\RRbackups\C\0\Data456 50003968 bytes
    File C:\RRbackups\C\0\Data457 50003968 bytes
    File C:\RRbackups\C\0\Data458 50003968 bytes
    File C:\RRbackups\C\0\Data459 50003968 bytes
    File C:\RRbackups\C\0\Data48 50003968 bytes
    File C:\RRbackups\C\0\Data480 50003968 bytes
    File C:\RRbackups\C\0\Data481 50003968 bytes
    File C:\RRbackups\C\0\Data482 50003968 bytes
    File C:\RRbackups\C\0\Data483 50003968 bytes
    File C:\RRbackups\C\0\Data484 50003968 bytes
    File C:\RRbackups\C\0\Data485 50003968 bytes
    File C:\RRbackups\C\0\Data486 50003968 bytes
    File C:\RRbackups\C\0\Data487 50003968 bytes
    File C:\RRbackups\C\0\Data488 50003968 bytes
    File C:\RRbackups\C\0\Data489 50003968 bytes
    File C:\RRbackups\C\0\Data49 50003968 bytes
    File C:\RRbackups\C\0\Data490 50003968 bytes
    File C:\RRbackups\C\0\Data491 50003968 bytes
    File C:\RRbackups\C\0\Data492 50003968 bytes
    File C:\RRbackups\C\0\Data493 50003968 bytes
    File C:\RRbackups\C\0\Data494 50003968 bytes
    File C:\RRbackups\C\0\Data495 50003968 bytes
    File C:\RRbackups\C\0\Data496 50003968 bytes
    File C:\RRbackups\C\0\Data497 50003968 bytes
    File C:\RRbackups\C\0\Data499 50003968 bytes
    File C:\RRbackups\C\0\Data5 50003968 bytes
    File C:\RRbackups\C\0\Data50 50003968 bytes
    File C:\RRbackups\C\0\Data500 50003968 bytes
    File C:\RRbackups\C\0\Data501 50003968 bytes
    File C:\RRbackups\C\0\Data502 50003968 bytes
    File C:\RRbackups\C\0\Data503 50003968 bytes
    File C:\RRbackups\C\0\Data504 50003968 bytes
    File C:\RRbackups\C\0\Data505 50003968 bytes
    File C:\RRbackups\C\0\Data506 50003968 bytes
    File C:\RRbackups\C\0\Data507 50003968 bytes
    File C:\RRbackups\C\0\Data508 50003968 bytes
    File C:\RRbackups\C\0\Data509 50003968 bytes
    File C:\RRbackups\C\0\Data51 50003968 bytes
    File C:\RRbackups\C\0\Data510 50003968 bytes
    File C:\RRbackups\C\0\Data511 50003968 bytes
    File C:\RRbackups\C\0\Data512 50003968 bytes
    File C:\RRbackups\C\0\Data513 50003968 bytes
    File C:\RRbackups\C\0\Data514 50003968 bytes
    File C:\RRbackups\C\0\Data515 50003968 bytes
    File C:\RRbackups\C\0\Data517 50003968 bytes
    File C:\RRbackups\C\0\Data518 50003968 bytes
    File C:\RRbackups\C\0\Data519 50003968 bytes
    File C:\RRbackups\C\0\Data52 50003968 bytes
    File C:\RRbackups\C\0\Data520 50003968 bytes
    File C:\RRbackups\C\0\Data521 50003968 bytes
    File C:\RRbackups\C\0\Data522 50003968 bytes
    File C:\RRbackups\C\0\Data523 50003968 bytes
    File C:\RRbackups\C\0\Data524 50003968 bytes
    File C:\RRbackups\C\0\Data525 50003968 bytes
    File C:\RRbackups\C\0\Data526 50003968 bytes
    File C:\RRbackups\C\0\Data527 50003968 bytes
    File C:\RRbackups\C\0\Data528 50003968 bytes
    File C:\RRbackups\C\0\Data529 50003968 bytes
    File C:\RRbackups\C\0\Data53 50003968 bytes
    File C:\RRbackups\C\0\Data530 50003968 bytes
    File C:\RRbackups\C\0\Data531 50003968 bytes
    File C:\RRbackups\C\0\Data532 50003968 bytes
    File C:\RRbackups\C\0\Data533 50003968 bytes
    File C:\RRbackups\C\0\Data534 50003968 bytes
    File C:\RRbackups\C\0\Data536 50003968 bytes
    File C:\RRbackups\C\0\Data537 50003968 bytes
    File C:\RRbackups\C\0\Data538 50003968 bytes
    File C:\RRbackups\C\0\Data539 50003968 bytes
    File C:\RRbackups\C\0\Data54 50003968 bytes
    File C:\RRbackups\C\0\Data540 50003968 bytes
    File C:\RRbackups\C\0\Data541 50003968 bytes
    File C:\RRbackups\C\0\Data542 50003968 bytes
    File C:\RRbackups\C\0\Data543 50003968 bytes
    File C:\RRbackups\C\0\Data544 50003968 bytes
    File C:\RRbackups\C\0\Data545 50003968 bytes
    File C:\RRbackups\C\0\Data546 50003968 bytes
    File C:\RRbackups\C\0\Data547 50003968 bytes
    File C:\RRbackups\C\0\Data548 50003968 bytes
    File C:\RRbackups\C\0\Data549 50003968 bytes
    File C:\RRbackups\C\0\Data55 50003968 bytes
    File C:\RRbackups\C\0\Data550 50003968 bytes
    File C:\RRbackups\C\0\Data551 50003968 bytes
    File C:\RRbackups\C\0\Data552 50003968 bytes
    File C:\RRbackups\C\0\Data553 50003968 bytes
    File C:\RRbackups\C\0\Data555 50003968 bytes
    File C:\RRbackups\C\0\Data556 50003968 bytes
    File C:\RRbackups\C\0\Data557 50003968 bytes
    File C:\RRbackups\C\0\Data558 50003968 bytes
    File C:\RRbackups\C\0\Data559 50003968 bytes
    File C:\RRbackups\C\0\Data56 50003968 bytes
    File C:\RRbackups\C\0\Data560 50003968 bytes
    File C:\RRbackups\C\0\Data561 50003968 bytes
    File C:\RRbackups\C\0\Data562 50003968 bytes
    File C:\RRbackups\C\0\Data563 50003968 bytes
    File C:\RRbackups\C\0\Data564 50003968 bytes
    File C:\RRbackups\C\0\Data565 50003968 bytes
    File C:\RRbackups\C\0\Data566 50003968 bytes
    File C:\RRbackups\C\0\Data567 50003968 bytes
    File C:\RRbackups\C\0\Data568 50003968 bytes
    File C:\RRbackups\C\0\Data569 50003968 bytes
    File C:\RRbackups\C\0\Data57 50003968 bytes
    File C:\RRbackups\C\0\Data570 50003968 bytes
    File C:\RRbackups\C\0\Data571 50003968 bytes
    File C:\RRbackups\C\0\Data572 50003968 bytes
    File C:\RRbackups\C\0\Data574 50003968 bytes
    File C:\RRbackups\C\0\Data575 50003968 bytes
    File C:\RRbackups\C\0\Data576 50003968 bytes
    File C:\RRbackups\C\0\Data577 50003968 bytes
    File C:\RRbackups\C\0\Data578 50003968 bytes
    File C:\RRbackups\C\0\Data579 50003968 bytes
    File C:\RRbackups\C\0\Data58 50003968 bytes
    File C:\RRbackups\C\0\Data580 50003968 bytes
    File C:\RRbackups\C\0\Data581 50003968 bytes
    File C:\RRbackups\C\0\Data582 50003968 bytes
    File C:\RRbackups\C\0\Data583 50003968 bytes
    File C:\RRbackups\C\0\Data584 50003968 bytes
    File C:\RRbackups\C\0\Data585 50003968 bytes
    File C:\RRbackups\C\0\Data586 50003968 bytes
    File C:\RRbackups\C\0\Data587 50003968 bytes
    File C:\RRbackups\C\0\Data588 50003968 bytes
    File C:\RRbackups\C\0\Data589 50003968 bytes
    File C:\RRbackups\C\0\Data59 50003968 bytes
    File C:\RRbackups\C\0\Data590 50003968 bytes
    File C:\RRbackups\C\0\Data591 50003968 bytes
    File C:\RRbackups\C\0\Data593 50003968 bytes
    File C:\RRbackups\C\0\Data594 50003968 bytes
    File C:\RRbackups\C\0\Data595 50003968 bytes
    File C:\RRbackups\C\0\Data596 50003968 bytes
    File C:\RRbackups\C\0\Data597 50003968 bytes
    File C:\RRbackups\C\0\Data598 50003968 bytes
    File C:\RRbackups\C\0\Data599 50003968 bytes
    File C:\RRbackups\C\0\Data6 50003968 bytes
    File C:\RRbackups\C\0\Data60 50003968 bytes
    File C:\RRbackups\C\0\Data600 50003968 bytes
    File C:\RRbackups\C\0\Data601 50003968 bytes
    File C:\RRbackups\C\0\Data602 50003968 bytes
    File C:\RRbackups\C\0\Data603 50003968 bytes
    File C:\RRbackups\C\0\Data604 50003968 bytes
    File C:\RRbackups\C\0\Data605 50003968 bytes
    File C:\RRbackups\C\0\Data606 50003968 bytes
    File C:\RRbackups\C\0\Data607 50003968 bytes
    File C:\RRbackups\C\0\Data608 50003968 bytes
    File C:\RRbackups\C\0\Data609 50003968 bytes
    File C:\RRbackups\C\0\Data61 50003968 bytes
    File C:\RRbackups\C\0\Data611 50003968 bytes
    File C:\RRbackups\C\0\Data612 50003968 bytes
    File C:\RRbackups\C\0\Data613 50003968 bytes
    File C:\RRbackups\C\0\Data614 50003968 bytes
    File C:\RRbackups\C\0\Data615 50003968 bytes
    File C:\RRbackups\C\0\Data616 50003968 bytes
    File C:\RRbackups\C\0\Data617 50003968 bytes
    File C:\RRbackups\C\0\Data618 50003968 bytes
    File C:\RRbackups\C\0\Data619 50003968 bytes
    File C:\RRbackups\C\0\Data62 50003968 bytes
    File C:\RRbackups\C\0\Data620 50003968 bytes
    File C:\RRbackups\C\0\Data621 50003968 bytes
    File C:\RRbackups\C\0\Data622 50003968 bytes
    File C:\RRbackups\C\0\Data623 50003968 bytes
    File C:\RRbackups\C\0\Data624 50003968 bytes
    File C:\RRbackups\C\0\Data625 50003968 bytes
    File C:\RRbackups\C\0\Data626 50003968 bytes
    File C:\RRbackups\C\0\Data627 50003968 bytes
    File C:\RRbackups\C\0\Data628 50003968 bytes
    File C:\RRbackups\C\0\Data629 50003968 bytes
    File C:\RRbackups\C\0\Data630 50003968 bytes
    File C:\RRbackups\C\0\Data631 50003968 bytes
    File C:\RRbackups\C\0\Data632 50003968 bytes
    File C:\RRbackups\C\0\Data633 50003968 bytes
    File C:\RRbackups\C\0\Data634 50003968 bytes
    File C:\RRbackups\C\0\Data635 50003968 bytes
    File C:\RRbackups\C\0\Data636 50003968 bytes
    File C:\RRbackups\C\0\Data637 50003968 bytes
    File C:\RRbackups\C\0\Data638 50003968 bytes
    File C:\RRbackups\C\0\Data639 50003968 bytes
    File C:\RRbackups\C\0\Data64 50003968 bytes
    File C:\RRbackups\C\0\Data640 50003968 bytes
    File C:\RRbackups\C\0\Data641 50003968 bytes
    File C:\RRbackups\C\0\Data642 50003968 bytes
    File C:\RRbackups\C\0\Data643 50003968 bytes
    File C:\RRbackups\C\0\Data644 50003968 bytes
    File C:\RRbackups\C\0\Data645 50003968 bytes
    File C:\RRbackups\C\0\Data646 50003968 bytes
    File C:\RRbackups\C\0\Data647 50003968 bytes
    File C:\RRbackups\C\0\Data648 50003968 bytes
    File C:\RRbackups\C\0\Data649 50003968 bytes
    File C:\RRbackups\C\0\Data840 50003968 bytes
    File C:\RRbackups\C\0\Data841 50003968 bytes
    File C:\RRbackups\C\0\Data842 50003968 bytes
    File C:\RRbackups\C\0\Data843 50003968 bytes
    File C:\RRbackups\C\0\Data844 50003968 bytes
    File C:\RRbackups\C\0\Data845 50003968 bytes
    File C:\RRbackups\C\0\Data846 50003968 bytes
    File C:\RRbackups\C\0\Data847 50003968 bytes
    File C:\RRbackups\C\0\Data848 50003968 bytes
    File C:\RRbackups\C\0\Data849 50003968 bytes
    File C:\RRbackups\C\0\Data85 50003968 bytes
    File C:\RRbackups\C\0\Data850 50003968 bytes
    File C:\RRbackups\C\0\Data851 50003968 bytes
    File C:\RRbackups\C\0\Data852 50003968 bytes
    File C:\RRbackups\C\0\Data853 50003968 bytes
    File C:\RRbackups\C\0\Data854 50003968 bytes
    File C:\RRbackups\C\0\Data855 50003968 bytes
    File C:\RRbackups\C\0\Data856 50003968 bytes
    File C:\RRbackups\C\0\Data857 50003968 bytes
    File C:\RRbackups\C\0\Data858 50003968 bytes
    File C:\RRbackups\C\0\Data67 50003968 bytes
    File C:\RRbackups\C\0\Data670 50003968 bytes
    File C:\RRbackups\C\0\Data671 50003968 bytes
    File C:\RRbackups\C\0\Data672 50003968 bytes
    File C:\RRbackups\C\0\Data673 50003968 bytes
    File C:\RRbackups\C\0\Data674 50003968 bytes
    File C:\RRbackups\C\0\Data675 50003968 bytes
    File C:\RRbackups\C\0\Data676 50003968 bytes
    File C:\RRbackups\C\0\Data677 50003968 bytes
    File C:\RRbackups\C\0\Data678 50003968 bytes
    File C:\RRbackups\C\0\Data679 50003968 bytes
    File C:\RRbackups\C\0\Data68 50003968 bytes
    File C:\RRbackups\C\0\Data680 50003968 bytes
    File C:\RRbackups\C\0\Data681 50003968 bytes
    File C:\RRbackups\C\0\Data682 50003968 bytes
    File C:\RRbackups\C\0\Data683 50003968 bytes
    File C:\RRbackups\C\0\Data684 50003968 bytes
    File C:\RRbackups\C\0\Data685 50003968 bytes
    File C:\RRbackups\C\0\Data686 50003968 bytes
    File C:\RRbackups\C\0\Data687 50003968 bytes
    File C:\RRbackups\C\0\Data689 50003968 bytes
    File C:\RRbackups\C\0\Data69 50003968 bytes
    File C:\RRbackups\C\0\Data690 50003968 bytes
    File C:\RRbackups\C\0\Data691 50003968 bytes
    File C:\RRbackups\C\0\Data692 50003968 bytes
    File C:\RRbackups\C\0\Data693 50003968 bytes
    File C:\RRbackups\C\0\Data694 50003968 bytes
    File C:\RRbackups\C\0\Data695 50003968 bytes
    File C:\RRbackups\C\0\Data696 50003968 bytes
    File C:\RRbackups\C\0\Data697 50003968 bytes
    File C:\RRbackups\C\0\Data698 50003968 bytes
    File C:\RRbackups\C\0\Data699 50003968 bytes
    File C:\RRbackups\C\0\Data7 50003968 bytes
    File C:\RRbackups\C\0\Data70 50003968 bytes
    File C:\RRbackups\C\0\Data700 50003968 bytes
    File C:\RRbackups\C\0\Data701 50003968 bytes
    File C:\RRbackups\C\0\Data702 50003968 bytes
    File C:\RRbackups\C\0\Data703 50003968 bytes
    File C:\RRbackups\C\0\Data704 50003968 bytes
    File C:\RRbackups\C\0\Data705 50003968 bytes
    File C:\RRbackups\C\0\Data707 50003968 bytes
    File C:\RRbackups\C\0\Data708 50003968 bytes
    File C:\RRbackups\C\0\Data709 50003968 bytes
    File C:\RRbackups\C\0\Data71 50003968 bytes
    File C:\RRbackups\C\0\Data710 50003968 bytes
    File C:\RRbackups\C\0\Data711 50003968 bytes
    File C:\RRbackups\C\0\Data712 50003968 bytes
    File C:\RRbackups\C\0\Data713 50003968 bytes
    File C:\RRbackups\C\0\Data714 50003968 bytes
    File C:\RRbackups\C\0\Data715 50003968 bytes
    File C:\RRbackups\C\0\Data716 50003968 bytes
    File C:\RRbackups\C\0\Data717 50003968 bytes
    File C:\RRbackups\C\0\Data718 50003968 bytes
    File C:\RRbackups\C\0\Data719 50003968 bytes
    File C:\RRbackups\C\0\Data72 50003968 bytes
    File C:\RRbackups\C\0\Data720 50003968 bytes
    File C:\RRbackups\C\0\Data721 50003968 bytes
    File C:\RRbackups\C\0\Data722 50003968 bytes
    File C:\RRbackups\C\0\Data723 50003968 bytes
    File C:\RRbackups\C\0\Data724 50003968 bytes
    File C:\RRbackups\C\0\Data726 50003968 bytes
    File C:\RRbackups\C\0\Data727 50003968 bytes
    File C:\RRbackups\C\0\Data728 50003968 bytes
    File C:\RRbackups\C\0\Data729 50003968 bytes
    File C:\RRbackups\C\0\Data73 50003968 bytes
    File C:\RRbackups\C\0\Data730 50003968 bytes
    File C:\RRbackups\C\0\Data731 50003968 bytes
    File C:\RRbackups\C\0\Data732 50003968 bytes
    File C:\RRbackups\C\0\Data733 50003968 bytes
    File C:\RRbackups\C\0\Data734 50003968 bytes
    File C:\RRbackups\C\0\Data735 50003968 bytes
    File C:\RRbackups\C\0\Data736 50003968 bytes
    File C:\RRbackups\C\0\Data737 50003968 bytes
    File C:\RRbackups\C\0\Data738 50003968 bytes
    File C:\RRbackups\C\0\Data739 50003968 bytes
    File C:\RRbackups\C\0\Data74 50003968 bytes
    File C:\RRbackups\C\0\Data740 50003968 bytes
    File C:\RRbackups\C\0\Data741 50003968 bytes
    File C:\RRbackups\C\0\Data742 50003968 bytes
    File C:\RRbackups\C\0\Data743 50003968 bytes
    File C:\RRbackups\C\0\Data745 50003968 bytes
    File C:\RRbackups\C\0\Data746 50003968 bytes
    File C:\RRbackups\C\0\Data747 50003968 bytes
    File C:\RRbackups\C\0\Data748 50003968 bytes
    File C:\RRbackups\C\0\Data749 50003968 bytes
    File C:\RRbackups\C\0\Data75 50003968 bytes
    File C:\RRbackups\C\0\Data750 50003968 bytes
    File C:\RRbackups\C\0\Data751 50003968 bytes
    File C:\RRbackups\C\0\Data752 50003968 bytes
    File C:\RRbackups\C\0\Data753 50003968 bytes
    File C:\RRbackups\C\0\Data754 50003968 bytes
    File C:\RRbackups\C\0\Data755 50003968 bytes
    File C:\RRbackups\C\0\Data756 50003968 bytes
    File C:\RRbackups\C\0\Data757 50003968 bytes
    File C:\RRbackups\C\0\Data758 50003968 bytes
    File C:\RRbackups\C\0\Data759 50003968 bytes
    File C:\RRbackups\C\0\Data76 50003968 bytes
    File C:\RRbackups\C\0\Data760 50003968 bytes
    File C:\RRbackups\C\0\Data761 50003968 bytes
    File C:\RRbackups\C\0\Data762 50003968 bytes
    File C:\RRbackups\C\0\Data764 50003968 bytes
    File C:\RRbackups\C\0\Data765 50003968 bytes
    File C:\RRbackups\C\0\Data766 50003968 bytes
    File C:\RRbackups\C\0\Data767 50003968 bytes
    File C:\RRbackups\C\0\Data768 50003968 bytes
    File C:\RRbackups\C\0\Data769 50003968 bytes
    File C:\RRbackups\C\0\Data77 50003968 bytes
    File C:\RRbackups\C\0\Data770 50003968 bytes
    File C:\RRbackups\C\0\Data771 50003968 bytes
    File C:\RRbackups\C\0\Data772 50003968 bytes
    File C:\RRbackups\C\0\Data773 50003968 bytes
    File C:\RRbackups\C\0\Data774 50003968 bytes
    File C:\RRbackups\C\0\Data775 50003968 bytes
    File C:\RRbackups\C\0\Data776 50003968 bytes
    File C:\RRbackups\C\0\Data777 50003968 bytes
    File C:\RRbackups\C\0\Data778 50003968 bytes
    File C:\RRbackups\C\0\Data779 50003968 bytes
    File C:\RRbackups\C\0\Data78 50003968 bytes
    File C:\RRbackups\C\0\Data780 50003968 bytes
    File C:\RRbackups\C\0\Data781 50003968 bytes
    File C:\RRbackups\C\0\Data783 50003968 bytes
    File C:\RRbackups\C\0\Data784 50003968 bytes
    File C:\RRbackups\C\0\Data785 50003968 bytes
    File C:\RRbackups\C\0\Data786 50003968 bytes
    File C:\RRbackups\C\0\Data787 50003968 bytes
    File C:\RRbackups\C\0\Data788 50003968 bytes
    File C:\RRbackups\C\0\Data789 50003968 bytes
    File C:\RRbackups\C\0\Data79 50003968 bytes
    File C:\RRbackups\C\0\Data790 50003968 bytes
    File C:\RRbackups\C\0\Data791 50003968 bytes
    File C:\RRbackups\C\0\Data792 50003968 bytes
    File C:\RRbackups\C\0\Data793 50003968 bytes
    File C:\RRbackups\C\0\Data794 50003968 bytes
    File C:\RRbackups\C\0\Data795 50003968 bytes
    File C:\RRbackups\C\0\Data796 50003968 bytes
    File C:\RRbackups\C\0\Data797 50003968 bytes
    File C:\RRbackups\C\0\Data798 50003968 bytes
    File C:\RRbackups\C\0\Data799 50003968 bytes
    File C:\RRbackups\C\0\Data8 50003968 bytes
    File C:\RRbackups\C\0\Data80 50003968 bytes
    File C:\RRbackups\C\0\Data801 50003968 bytes
    File C:\RRbackups\C\0\Data802 50003968 bytes
    File C:\RRbackups\C\0\Data803 50003968 bytes
    File C:\RRbackups\C\0\Data804 50003968 bytes
    File C:\RRbackups\C\0\Data805 50003968 bytes
    File C:\RRbackups\C\0\Data806 50003968 bytes
    File C:\RRbackups\C\0\Data807 50003968 bytes
    File C:\RRbackups\C\0\Data808 50003968 bytes
    File C:\RRbackups\C\0\Data809 50003968 bytes
    File C:\RRbackups\C\0\Data81 50003968 bytes
    File C:\RRbackups\C\0\Data810 50003968 bytes
    File C:\RRbackups\C\0\Data811 50003968 bytes
    File C:\RRbackups\C\0\Data812 50003968 bytes
    File C:\RRbackups\C\0\Data813 50003968 bytes
    File C:\RRbackups\C\0\Data814 50003968 bytes
    File C:\RRbackups\C\0\Data815 50003968 bytes
    File C:\RRbackups\C\0\Data816 50003968 bytes
    File C:\RRbackups\C\0\Data817 50003968 bytes
    File C:\RRbackups\C\0\Data818 50003968 bytes
    File C:\RRbackups\C\0\Data819 50003968 bytes
    File C:\RRbackups\C\0\Data820 50003968 bytes
    File C:\RRbackups\C\0\Data821 50003968 bytes
    File C:\RRbackups\C\0\Data822 50003968 bytes
    File C:\RRbackups\C\0\Data823 50003968 bytes
    File C:\RRbackups\C\0\Data824 50003968 bytes
    File C:\RRbackups\C\0\Data825 50003968 bytes
    File C:\RRbackups\C\0\Data826 50003968 bytes
    File C:\RRbackups\C\0\Data827 50003968 bytes
    File C:\RRbackups\C\0\Data828 50003968 bytes
    File C:\RRbackups\C\0\Data829 50003968 bytes
    File C:\RRbackups\C\0\Data83 50003968 bytes
    File C:\RRbackups\C\0\Data830 50003968 bytes
    File C:\RRbackups\C\0\Data831 50003968 bytes
    File C:\RRbackups\C\0\Data832 50003968 bytes
    File C:\RRbackups\C\0\Data833 50003968 bytes
    File C:\RRbackups\C\0\Data834 50003968 bytes
    File C:\RRbackups\C\0\Data835 50003968 bytes
    File C:\RRbackups\C\0\Data836 50003968 bytes
    File C:\RRbackups\C\0\Data837 50003968 bytes
    File C:\RRbackups\C\0\Data838 50003968 bytes
    File C:\RRbackups\C\0\Data839 50003968 bytes
    File C:\RRbackups\C\0\Data498 50003968 bytes
    File C:\RRbackups\C\0\Data516 50003968 bytes
    File C:\RRbackups\C\0\Data535 50003968 bytes
    File C:\RRbackups\C\0\Data554 50003968 bytes
    File C:\RRbackups\C\0\Data573 50003968 bytes
    File C:\RRbackups\C\0\Data592 50003968 bytes
    File C:\RRbackups\C\0\Data610 50003968 bytes
    File C:\RRbackups\C\0\Data63 50003968 bytes
    File C:\RRbackups\C\0\Data65 50003968 bytes
    File C:\RRbackups\C\0\Data669 50003968 bytes
    File C:\RRbackups\C\0\Data688 50003968 bytes
    File C:\RRbackups\C\0\Data706 50003968 bytes
    File C:\RRbackups\C\0\Data725 50003968 bytes
    File C:\RRbackups\C\0\Data744 50003968 bytes
    File C:\RRbackups\C\0\Data763 50003968 bytes
    File C:\RRbackups\C\0\Data782 50003968 bytes
    File C:\RRbackups\C\0\Data800 50003968 bytes
    File C:\RRbackups\C\0\Data82 50003968 bytes
    File C:\RRbackups\C\0\Data84 50003968 bytes
    File C:\RRbackups\C\0\Data859 50003968 bytes
    File C:\RRbackups\C\0\Data878 50003968 bytes
    File C:\RRbackups\C\0\Data897 50003968 bytes
    File C:\RRbackups\C\0\Data915 50003968 bytes
    File C:\RRbackups\C\0\Data934 50003968 bytes
    File C:\RRbackups\C\0\Data953 50003968 bytes
    File C:\RRbackups\C\0\Data972 50003968 bytes
    File C:\RRbackups\C\0\Data86 50003968 bytes
    File C:\RRbackups\C\0\Data860 50003968 bytes
    File C:\RRbackups\C\0\Data861 50003968 bytes
    File C:\RRbackups\C\0\Data862 50003968 bytes
    File C:\RRbackups\C\0\Data863 50003968 bytes
    File C:\RRbackups\C\0\Data864 50003968 bytes
    File C:\RRbackups\C\0\Data865 50003968 bytes
    File C:\RRbackups\C\0\Data866 50003968 bytes
    File C:\RRbackups\C\0\Data867 50003968 bytes
    File C:\RRbackups\C\0\Data868 50003968 bytes
    File C:\RRbackups\C\0\Data869 50003968 bytes
    File C:\RRbackups\C\0\Data87 50003968 bytes
    File C:\RRbackups\C\0\Data870 50003968 bytes
    File C:\RRbackups\C\0\Data871 50003968 bytes
    File C:\RRbackups\C\0\Data872 50003968 bytes
    File C:\RRbackups\C\0\Data873 50003968 bytes
    File C:\RRbackups\C\0\Data874 50003968 bytes
    File C:\RRbackups\C\0\Data875 50003968 bytes
    File C:\RRbackups\C\0\Data876 50003968 bytes
    File C:\RRbackups\C\0\Data877 50003968 bytes
    File C:\RRbackups\C\0\Data879 50003968 bytes
    File C:\RRbackups\C\0\Data88 50003968 bytes
    File C:\RRbackups\C\0\Data880 50003968 bytes
    File C:\RRbackups\C\0\Data881 50003968 bytes
    File C:\RRbackups\C\0\Data882 50003968 bytes
    File C:\RRbackups\C\0\Data883 50003968 bytes
    File C:\RRbackups\C\0\Data884 50003968 bytes
    File C:\RRbackups\C\0\Data885 50003968 bytes
    File C:\RRbackups\C\0\Data886 50003968 bytes
    File C:\RRbackups\C\0\Data887 50003968 bytes
    File C:\RRbackups\C\0\Data888 50003968 bytes
    File C:\RRbackups\C\0\Data889 50003968 bytes
    File C:\RRbackups\C\0\Data89 50003968 bytes
    File C:\RRbackups\C\0\Data890 50003968 bytes
    File C:\RRbackups\C\0\Data891 50003968 bytes
    File C:\RRbackups\C\0\Data892 50003968 bytes
    File C:\RRbackups\C\0\Data893 50003968 bytes
    File C:\RRbackups\C\0\Data894 50003968 bytes
    File C:\RRbackups\C\0\Data895 50003968 bytes
    File C:\RRbackups\C\0\Data896 50003968 bytes
    File C:\RRbackups\C\0\Data898 50003968 bytes
    File C:\RRbackups\C\0\Data899 50003968 bytes
    File C:\RRbackups\C\0\Data9 50003968 bytes
    File C:\RRbackups\C\0\Data90 50003968 bytes
    File C:\RRbackups\C\0\Data900 50003968 bytes
    File C:\RRbackups\C\0\Data901 50003968 bytes
    File C:\RRbackups\C\0\Data902 50003968 bytes
    File C:\RRbackups\C\0\Data903 50003968 bytes
    File C:\RRbackups\C\0\Data904 50003968 bytes
    File C:\RRbackups\C\0\Data905 50003968 bytes
    File C:\RRbackups\C\0\Data906 50003968 bytes
    File C:\RRbackups\C\0\Data907 50003968 bytes
    File C:\RRbackups\C\0\Data908 50003968 bytes
    File C:\RRbackups\C\0\Data909 50003968 bytes
    File C:\RRbackups\C\0\Data91 50003968 bytes
    File C:\RRbackups\C\0\Data910 50003968 bytes
    File C:\RRbackups\C\0\Data911 50003968 bytes
    File C:\RRbackups\C\0\Data912 50003968 bytes
    File C:\RRbackups\C\0\Data913 50003968 bytes
    File C:\RRbackups\C\0\Data914 50003968 bytes
    File C:\RRbackups\C\0\Data916 50003968 bytes
    File C:\RRbackups\C\0\Data917 50003968 bytes
    File C:\RRbackups\C\0\Data918 50003968 bytes
    File C:\RRbackups\C\0\Data919 50003968 bytes
    File C:\RRbackups\C\0\Data92 50003968 bytes
    File C:\RRbackups\C\0\Data920 50003968 bytes
    File C:\RRbackups\C\0\Data921 50003968 bytes
    File C:\RRbackups\C\0\Data922 50003968 bytes
    File C:\RRbackups\C\0\Data923 50003968 bytes
    File C:\RRbackups\C\0\Data924 50003968 bytes
    File C:\RRbackups\C\0\Data925 50003968 bytes
    File C:\RRbackups\C\0\Data926 50003968 bytes
    File C:\RRbackups\C\0\Data927 50003968 bytes
    File C:\RRbackups\C\0\Data928 50003968 bytes
    File C:\RRbackups\C\0\Data929 50003968 bytes
    File C:\RRbackups\C\0\Data93 50003968 bytes
    File C:\RRbackups\C\0\Data930 50003968 bytes
    File C:\RRbackups\C\0\Data931 50003968 bytes
    File C:\RRbackups\C\0\Data932 50003968 bytes
    File C:\RRbackups\C\0\Data933 50003968 bytes
    File C:\RRbackups\C\0\Data935 50003968 bytes
    File C:\RRbackups\C\0\Data936 50003968 bytes
    File C:\RRbackups\C\0\Data937 50003968 bytes
    File C:\RRbackups\C\0\Data938 50003968 bytes
    File C:\RRbackups\C\0\Data939 50003968 bytes
    File C:\RRbackups\C\0\Data94 50003968 bytes
    File C:\RRbackups\C\0\Data940 50003968 bytes
    File C:\RRbackups\C\0\Data941 50003968 bytes
    File C:\RRbackups\C\0\Data942 50003968 bytes
    File C:\RRbackups\C\0\Data943 50003968 bytes
    File C:\RRbackups\C\0\Data944 50003968 bytes
    File C:\RRbackups\C\0\Data945 50003968 bytes
    File C:\RRbackups\C\0\Data946 50003968 bytes
    File C:\RRbackups\C\0\Data947 50003968 bytes
    File C:\RRbackups\C\0\Data948 50003968 bytes
    File C:\RRbackups\C\0\Data949 50003968 bytes
    File C:\RRbackups\C\0\Data95 50003968 bytes
    File C:\RRbackups\C\0\Data950 50003968 bytes
    File C:\RRbackups\C\0\Data951 50003968 bytes
    File C:\RRbackups\C\0\Data952 50003968 bytes
    File C:\RRbackups\C\0\Data954 50003968 bytes
    File C:\RRbackups\C\0\Data955 50003968 bytes
    File C:\RRbackups\C\0\Data956 50003968 bytes
    File C:\RRbackups\C\0\Data957 50003968 bytes
    File C:\RRbackups\C\0\Data958 50003968 bytes
    File C:\RRbackups\C\0\Data959 50003968 bytes
    File C:\RRbackups\C\0\Data96 50003968 bytes
    File C:\RRbackups\C\0\Data960 50003968 bytes
    File C:\RRbackups\C\0\Data961 50003968 bytes
    File C:\RRbackups\C\0\Data962 50003968 bytes
    File C:\RRbackups\C\0\Data963 50003968 bytes
    File C:\RRbackups\C\0\Data964 50003968 bytes
    File C:\RRbackups\C\0\Data965 50003968 bytes
    File C:\RRbackups\C\0\Data966 50003968 bytes
    File C:\RRbackups\C\0\Data967 50003968 bytes
    File C:\RRbackups\C\0\Data968 50003968 bytes
    File C:\RRbackups\C\0\Data969 50003968 bytes
    File C:\RRbackups\C\0\Data97 50003968 bytes
    File C:\RRbackups\C\0\Data970 50003968 bytes
    File C:\RRbackups\C\0\Data971 50003968 bytes
    File C:\RRbackups\C\0\Data973 50003968 bytes
    File C:\RRbackups\C\0\Data974 50003968 bytes
    File C:\RRbackups\C\0\Data975 50003968 bytes
    File C:\RRbackups\C\0\Data976 50003968 bytes
    File C:\RRbackups\C\0\Data977 50003968 bytes
    File C:\RRbackups\C\0\Data978 50003968 bytes
    File C:\RRbackups\C\0\Data979 50003968 bytes
    File C:\RRbackups\C\0\Data98 50003968 bytes
    File C:\RRbackups\C\0\Data980 50003968 bytes
    File C:\RRbackups\C\0\Data981 50003968 bytes
    File C:\RRbackups\C\0\Data982 50003968 bytes
    File C:\RRbackups\C\0\Data983 50003968 bytes
    File C:\RRbackups\C\0\Data984 50003968 bytes
    File C:\RRbackups\C\0\Data985 50003968 bytes
    File C:\RRbackups\C\0\Data986 50003968 bytes
    File C:\RRbackups\C\0\Data987 50003968 bytes
    File C:\RRbackups\C\0\Data988 50003968 bytes
    File C:\RRbackups\C\0\Data989 50003968 bytes
    File C:\RRbackups\C\0\Data99 50003968 bytes
    File C:\RRbackups\C\0\Data990 50003968 bytes
    File C:\RRbackups\C\0\Data991 50003968 bytes
    File C:\RRbackups\C\0\Data992 50003968 bytes
    File C:\RRbackups\C\0\Data993 50003968 bytes
    File C:\RRbackups\C\0\Data994 50003968 bytes
    File C:\RRbackups\C\0\Data995 50003968 bytes
    File C:\RRbackups\C\0\Data996 50003968 bytes
    File C:\RRbackups\C\0\Data997 50003968 bytes
    File C:\RRbackups\C\0\Data998 50003968 bytes
    File C:\RRbackups\C\0\Data999 50003968 bytes
    File C:\RRbackups\C\0\dats 0 bytes
    File C:\RRbackups\C\0\EFSFile 0 bytes
    File C:\RRbackups\C\0\HashFile 1912506 bytes
    File C:\RRbackups\C\0\Info 756 bytes
    File C:\RRbackups\C\0\TOCFile 194438110 bytes
    File C:\RRbackups\C\1 0 bytes
    File C:\RRbackups\C\1\Data27 50003968 bytes
    File C:\RRbackups\C\1\Data46 50003968 bytes
    File C:\RRbackups\C\1\Data65 50003968 bytes
    File C:\RRbackups\C\1\Data84 50003968 bytes
    File C:\RRbackups\C\1\Data0 50003968 bytes
    File C:\RRbackups\C\1\Data1 50003968 bytes
    File C:\RRbackups\C\1\Data10 50003968 bytes
    File C:\RRbackups\C\1\Data100 50003968 bytes
    File C:\RRbackups\C\1\Data101 50003968 bytes
    File C:\RRbackups\C\1\Data102 50003968 bytes
    File C:\RRbackups\C\1\Data103 50003968 bytes
    File C:\RRbackups\C\1\Data104 50003968 bytes
    File C:\RRbackups\C\1\Data105 26728315 bytes
    File C:\RRbackups\C\1\Data11 50003968 bytes
    File C:\RRbackups\C\1\Data12 50003968 bytes
    File C:\RRbackups\C\1\Data13 50003968 bytes
    File C:\RRbackups\C\1\Data14 50003968 bytes
    File C:\RRbackups\C\1\Data15 50003968 bytes
    File C:\RRbackups\C\1\Data16 50003968 bytes
    File C:\RRbackups\C\1\Data17 50003968 bytes
    File C:\RRbackups\C\1\Data18 50003968 bytes
    File C:\RRbackups\C\1\Data19 50003968 bytes
    File C:\RRbackups\C\1\Data2 50003968 bytes
    File C:\RRbackups\C\1\Data20 50003968 bytes
    File C:\RRbackups\C\1\Data21 50003968 bytes
    File C:\RRbackups\C\1\Data22 50003968 bytes
    File C:\RRbackups\C\1\Data23 50003968 bytes
    File C:\RRbackups\C\1\Data24 50003968 bytes
    File C:\RRbackups\C\1\Data25 50003968 bytes
    File C:\RRbackups\C\1\Data26 50003968 bytes
    File C:\RRbackups\C\1\Data28 50003968 bytes
    File C:\RRbackups\C\1\Data29 50003968 bytes
    File C:\RRbackups\C\1\Data3 50003968 bytes
    File C:\RRbackups\C\1\Data30 50003968 bytes
    File C:\RRbackups\C\1\Data31 50003968 bytes
    File C:\RRbackups\C\1\Data32 50003968 bytes
    File C:\RRbackups\C\1\Data33 50003968 bytes
    File C:\RRbackups\C\1\Data34 50003968 bytes
    File C:\RRbackups\C\1\Data35 50003968 bytes
    File C:\RRbackups\C\1\Data36 50003968 bytes
    File C:\RRbackups\C\1\Data37 50003968 bytes
    File C:\RRbackups\C\1\Data38 50003968 bytes
    File C:\RRbackups\C\1\Data39 50003968 bytes
    File C:\RRbackups\C\1\Data4 50003968 bytes
    File C:\RRbackups\C\1\Data40 50003968 bytes
    File C:\RRbackups\C\1\Data41 50003968 bytes
    File C:\RRbackups\C\1\Data42 50003968 bytes
    File C:\RRbackups\C\1\Data43 50003968 bytes
    File C:\RRbackups\C\1\Data44 50003968 bytes
    File C:\RRbackups\C\1\Data45 50003968 bytes
    File C:\RRbackups\C\1\Data47 50003968 bytes
    File C:\RRbackups\C\1\Data48 50003968 bytes
    File C:\RRbackups\C\1\Data49 50003968 bytes
    File C:\RRbackups\C\1\Data5 50003968 bytes
    File C:\RRbackups\C\1\Data50 50003968 bytes
    File C:\RRbackups\C\1\Data51 50003968 bytes
    File C:\RRbackups\C\1\Data52 50003968 bytes
    File C:\RRbackups\C\1\Data53 50003968 bytes
    File C:\RRbackups\C\1\Data54 50003968 bytes
    File C:\RRbackups\C\1\Data55 50003968 bytes
    File C:\RRbackups\C\1\Data56 50003968 bytes
    File C:\RRbackups\C\1\Data57 50003968 bytes
    File C:\RRbackups\C\1\Data58 50003968 bytes
    File C:\RRbackups\C\1\Data59 50003968 bytes
    File C:\RRbackups\C\1\Data6 50003968 bytes
    File C:\RRbackups\C\1\Data60 50003968 bytes
    File C:\RRbackups\C\1\Data61 50003968 bytes
    File C:\RRbackups\C\1\Data62 50003968 bytes
    File C:\RRbackups\C\1\Data63 50003968 bytes
    File C:\RRbackups\C\1\Data64 50003968 bytes
    File C:\RRbackups\C\1\Data66 50003968 bytes
    File C:\RRbackups\C\1\Data67 50003968 bytes
    File C:\RRbackups\C\1\Data68 50003968 bytes
    File C:\RRbackups\C\1\Data69 50003968 bytes
    File C:\RRbackups\C\1\Data7 50003968 bytes
    File C:\RRbackups\C\1\Data70 50003968 bytes
    File C:\RRbackups\C\1\Data71 50003968 bytes
    File C:\RRbackups\C\1\Data72 50003968 bytes
    File C:\RRbackups\C\1\Data73 50003968 bytes
    File C:\RRbackups\C\1\Data74 50003968 bytes
    File C:\RRbackups\C\1\Data75 50003968 bytes
    File C:\RRbackups\C\1\Data76 50003968 bytes
    File C:\RRbackups\C\1\Data77 50003968 bytes
    File C:\RRbackups\C\1\Data78 50003968 bytes
    File C:\RRbackups\C\1\Data79 50003968 bytes
    File C:\RRbackups\C\1\Data8 50003968 bytes
    File C:\RRbackups\C\1\Data80 50003968 bytes
    File C:\RRbackups\C\1\Data81 50003968 bytes
    File C:\RRbackups\C\1\Data82 50003968 bytes
    File C:\RRbackups\C\1\Data83 50003968 bytes
    File C:\RRbackups\C\1\Data85 50003968 bytes
    File C:\RRbackups\C\1\Data86 50003968 bytes
    File C:\RRbackups\C\1\Data87 50003968 bytes
    File C:\RRbackups\C\1\Data88 50003968 bytes
    File C:\RRbackups\C\1\Data89 50003968 bytes
    File C:\RRbackups\C\1\Data9 50003968 bytes
    File C:\RRbackups\C\1\Data90 50003968 bytes
    File C:\RRbackups\C\1\Data91 50003968 bytes
    File C:\RRbackups\C\1\Data92 50003968 bytes
    File C:\RRbackups\C\1\Data93 50003968 bytes
    File C:\RRbackups\C\1\Data94 50003968 bytes
    File C:\RRbackups\C\1\Data95 50003968 bytes
    File C:\RRbackups\C\1\Data96 50003968 bytes
    File C:\RRbackups\C\1\Data97 50003968 bytes
    File C:\RRbackups\C\1\Data98 50003968 bytes
    File C:\RRbackups\C\1\Data99 50003968 bytes
    File C:\RRbackups\C\1\dats 0 bytes
    File C:\RRbackups\C\1\EFSFile 0 bytes
    File C:\RRbackups\C\1\HashFile 1979082 bytes
    File C:\RRbackups\C\1\Info 756 bytes
    File C:\RRbackups\C\1\TOCFile 201206670 bytes
    File C:\RRbackups\common 0 bytes
    File C:\RRbackups\common\backups.dat 8192 bytes
    File C:\RRbackups\common\bmgrmode.dat 29 bytes
    File C:\RRbackups\common\bt0.dat 32256 bytes
    File C:\RRbackups\common\bt1.dat 32256 bytes
    File C:\RRbackups\common\css.dat 8192 bytes
    File C:\RRbackups\common\hints.dat 8192 bytes
    File C:\RRbackups\common\mnd.dat 8192 bytes
    File C:\RRbackups\common\regcerts.dat 8192 bytes
    File C:\RRbackups\common\restore.log 110 bytes
    File C:\RRbackups\common\rr.log 94046 bytes
    File C:\RRbackups\common\rr_bcdenum.dat 4168 bytes
    File C:\RRbackups\common\SAM 262144 bytes
    File C:\RRbackups\common\secpolicy.dat 20480 bytes
    File C:\RRbackups\common\settings.dat 32768 bytes
    File C:\RRbackups\common\system.dat 12288 bytes
    File C:\RRbackups\common\tvtcmn.dat 8192 bytes
    File C:\RRbackups\common\tvtns.bin 23 bytes
    File C:\RRbackups\common\usersids.dat 20800 bytes
    File C:\RRbackups\Documents and Settings 0 bytes
    File C:\RRbackups\Documents and Settings\Administrator 0 bytes
    File C:\RRbackups\Documents and Settings\Administrator\AppData 0 bytes
    File C:\RRbackups\Documents and Settings\Administrator\AppData\Roaming 0 bytes
    File C:\RRbackups\Documents and Settings\Administrator\AppData\Roaming\Microsoft 0 bytes
    File C:\RRbackups\Documents and Settings\Administrator\AppData\Roaming\Microsoft\C rypto 0 bytes
    File C:\RRbackups\Documents and Settings\Administrator\AppData\Roaming\Microsoft\C rypto\RSA 0 bytes
    File C:\RRbackups\Documents and Settings\Administrator\AppData\Roaming\Microsoft\C rypto\RSA\S-1-5-21-432148126-3170665589-795329589-500 0 bytes
    File C:\RRbackups\Documents and Settings\Administrator\AppData\Roaming\Microsoft\C rypto\RSA\S-1-5-21-432148126-3170665589-795329589-500\8f71098770f72c7a67cd8f1151619865_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 54 bytes
    File C:\RRbackups\Documents and Settings\Administrator\AppData\Roaming\Microsoft\P rotect 0 bytes
    File C:\RRbackups\Documents and Settings\Administrator\AppData\Roaming\Microsoft\P rotect\CREDHIST 24 bytes
    File C:\RRbackups\Documents and Settings\Administrator\AppData\Roaming\Microsoft\P rotect\S-1-5-21-2954931239-385123427-3653054573-500 0 bytes
    File C:\RRbackups\Documents and Settings\Administrator\AppData\Roaming\Microsoft\P rotect\S-1-5-21-2954931239-385123427-3653054573-500\3a1b7501-4387-496f-a860-64554f41ab50 388 bytes
    File C:\RRbackups\Documents and Settings\Administrator\AppData\Roaming\Microsoft\P rotect\S-1-5-21-2954931239-385123427-3653054573-500\Preferred 24 bytes
    File C:\RRbackups\Documents and Settings\Administrator\AppData\Roaming\Microsoft\P rotect\S-1-5-21-432148126-3170665589-795329589-500 0 bytes
    File C:\RRbackups\Documents and Settings\Administrator\AppData\Roaming\Microsoft\P rotect\S-1-5-21-432148126-3170665589-795329589-500\a9d39b00-924f-4c0c-853b-5f7fcb676fad 388 bytes
    File C:\RRbackups\Documents and Settings\Administrator\AppData\Roaming\Microsoft\P rotect\S-1-5-21-432148126-3170665589-795329589-500\Preferred 24 bytes
    File C:\RRbackups\Documents and Settings\Administrator\AppData\Roaming\Microsoft\S ystemCertificates 0 bytes
    File C:\RRbackups\Documents and Settings\Administrator\AppData\Roaming\Microsoft\S ystemCertificates\My 0 bytes
    File C:\RRbackups\Documents and Settings\Administrator\AppData\Roaming\Microsoft\S ystemCertificates\My\Certificates 0 bytes
    File C:\RRbackups\Documents and Settings\Administrator\AppData\Roaming\Microsoft\S ystemCertificates\My\CRLs 0 bytes
    File C:\RRbackups\Documents and Settings\Administrator\AppData\Roaming\Microsoft\S ystemCertificates\My\CTLs 0 bytes
    File C:\RRbackups\Documents and Settings\lqi 0 bytes
    File C:\RRbackups\Documents and Settings\lqi\AppData 0 bytes
    File C:\RRbackups\Documents and Settings\lqi\AppData\Roaming 0 bytes
    File C:\RRbackups\Documents and Settings\lqi\AppData\Roaming\Lenovo 0 bytes
    File C:\RRbackups\Documents and Settings\lqi\AppData\Roaming\Lenovo\Client Security Solution 0 bytes
    File C:\RRbackups\Documents and Settings\lqi\AppData\Roaming\Lenovo\Client Security Solution\enroll.ini 32 bytes
    File C:\RRbackups\Documents and Settings\lqi\AppData\Roaming\Lenovo\Client Security Solution\hibernation.dat 4 bytes
    File C:\RRbackups\Documents and Settings\lqi\AppData\Roaming\Microsoft 0 bytes
    File C:\RRbackups\Documents and Settings\lqi\AppData\Roaming\Microsoft\Crypto 0 bytes
    File C:\RRbackups\Documents and Settings\lqi\AppData\Roaming\Microsoft\Crypto\RSA 0 bytes
    File C:\RRbackups\Documents and Settings\lqi\AppData\Roaming\Microsoft\Crypto\RSA\ S-1-5-21-432148126-3170665589-795329589-1003 0 bytes
    File C:\RRbackups\Documents and Settings\lqi\AppData\Roaming\Microsoft\Crypto\RSA\ S-1-5-21-432148126-3170665589-795329589-1003\340c8499eaf8cbb14bea44864100070c_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1332 bytes
    File C:\RRbackups\Documents and Settings\lqi\AppData\Roaming\Microsoft\Crypto\RSA\ S-1-5-21-432148126-3170665589-795329589-1003\62a45886e06c7d046ea8b819bec0598a_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 45 bytes
    File C:\RRbackups\Documents and Settings\lqi\AppData\Roaming\Microsoft\Crypto\RSA\ S-1-5-21-432148126-3170665589-795329589-1003\6b29ae44e85efac3c72ff4d1865d73f1_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 53 bytes
    File C:\RRbackups\Documents and Settings\lqi\AppData\Roaming\Microsoft\Crypto\RSA\ S-1-5-21-432148126-3170665589-795329589-1003\7d8bfe4931d42bc369eef7d8b6f1b4c9_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1332 bytes
    File C:\RRbackups\Documents and Settings\lqi\AppData\Roaming\Microsoft\Crypto\RSA\ S-1-5-21-432148126-3170665589-795329589-1003\7fa9c2d66826f040a06f48e635c17041_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1332 bytes
    File C:\RRbackups\Documents and Settings\lqi\AppData\Roaming\Microsoft\Crypto\RSA\ S-1-5-21-432148126-3170665589-795329589-1003\83aa4cc77f591dfc2374580bbd95f6ba_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 45 bytes
    File C:\RRbackups\Documents and Settings\lqi\AppData\Roaming\Microsoft\Crypto\RSA\ S-1-5-21-432148126-3170665589-795329589-1003\8f71098770f72c7a67cd8f1151619865_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 54 bytes
    File C:\RRbackups\Documents and Settings\lqi\AppData\Roaming\Microsoft\Crypto\RSA\ S-1-5-21-432148126-3170665589-795329589-1003\ad26b2bffb3e99f6133cb56b56a0014d_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1332 bytes
    File C:\RRbackups\Documents and Settings\lqi\AppData\Roaming\Microsoft\Protect 0 bytes
    File C:\RRbackups\Documents and Settings\lqi\AppData\Roaming\Microsoft\Protect\CRE DHIST 24 bytes
    File C:\RRbackups\Documents and Settings\lqi\AppData\Roaming\Microsoft\Protect\S-1-5-21-432148126-3170665589-795329589-1003 0 bytes
    File C:\RRbackups\Documents and Settings\lqi\AppData\Roaming\Microsoft\Protect\S-1-5-21-432148126-3170665589-795329589-1003\2497295e-a6ff-4d9b-8c3c-b846023f3cb0 388 bytes
    File C:\RRbackups\Documents and Settings\lqi\AppData\Roaming\Microsoft\Protect\S-1-5-21-432148126-3170665589-795329589-1003\35d352e9-6cec-4708-9ebd-37785d7ff08d 388 bytes
    File C:\RRbackups\Documents and Settings\lqi\AppData\Roaming\Microsoft\Protect\S-1-5-21-432148126-3170665589-795329589-1003\4c311c10-8d5f-412d-b0a6-67c7e7628e78 388 bytes
    File C:\RRbackups\Documents and Settings\lqi\AppData\Roaming\Microsoft\Protect\S-1-5-21-432148126-3170665589-795329589-1003\64c343be-675b-4ff6-a575-45165fa27677 388 bytes
    File C:\RRbackups\Documents and Settings\lqi\AppData\Roaming\Microsoft\Protect\S-1-5-21-432148126-3170665589-795329589-1003\8ad852a9-1a5b-45f0-b554-1ef9e31db8f8 388 bytes
    File C:\RRbackups\Documents and Settings\lqi\AppData\Roaming\Microsoft\Protect\S-1-5-21-432148126-3170665589-795329589-1003\a55e2e77-34b6-4433-ba52-8785b77ed22c 388 bytes
    File C:\RRbackups\Documents and Settings\lqi\AppData\Roaming\Microsoft\Protect\S-1-5-21-432148126-3170665589-795329589-1003\d487cdff-bf61-46b0-b6a1-aad5b2587fdd 388 bytes
    File C:\RRbackups\Documents and Settings\lqi\AppData\Roaming\Microsoft\Protect\S-1-5-21-432148126-3170665589-795329589-1003\fdc614d8-6bc1-41b6-a91d-2c543e672e05 388 bytes
    File C:\RRbackups\Documents and Settings\lqi\AppData\Roaming\Microsoft\Protect\S-1-5-21-432148126-3170665589-795329589-1003\Preferred 24 bytes
    File C:\RRbackups\Documents and Settings\lqi\AppData\Roaming\Microsoft\SystemCerti ficates 0 bytes
    File C:\RRbackups\Documents and Settings\lqi\AppData\Roaming\Microsoft\SystemCerti ficates\My 0 bytes
    File C:\RRbackups\Documents and Settings\lqi\AppData\Roaming\Microsoft\SystemCerti ficates\My\Certificates 0 bytes
    File C:\RRbackups\Documents and Settings\lqi\AppData\Roaming\Microsoft\SystemCerti ficates\My\CRLs 0 bytes
    File C:\RRbackups\Documents and Settings\lqi\AppData\Roaming\Microsoft\SystemCerti ficates\My\CTLs 0 bytes
    File C:\RRbackups\ProgramData 0 bytes
    File C:\RRbackups\ProgramData\Microsoft 0 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto 0 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA 0 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys 0 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\02dfef17062ef2431843d47ec606106b_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1305 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\04836675d4aef5970c10786062c1ef4f_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 77 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\051b13e309d8e929368f0f184e1cd6b9_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1305 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\0bb6bf26f4b4223cf2ce5f15320258f1_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 77 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\0fd79e0df429ed8b6ad56d35e97900bc_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1305 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\135128de7da34765902b3ac2a15b53fb_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 77 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\228b3307ee120960fa7bc981f11b07f1_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 77 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\29e82af4afc767035851101cbb096093_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 77 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\2c2a3076aa9452873d11869b5b82545d_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 77 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\35461bc1efa0e88721435b76a1458417_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1305 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\3d44ba49e15c263e23fc9f25f98df788_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 77 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\3dd558fa5de4219da717374594e58574_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 77 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\3e9fd40d700297ec091a0a2abeffc896_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 77 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\3f9d8f0cb42f7952b1d1aa5400d3f029_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 77 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\43d1049338eb06a6f576124429028959_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1305 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\45a8a926ee21a614cbd7fe632749dd40_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 77 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\492932733e5be048e4eb5316d2915bfa_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 77 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\4b743ca12f2bd13d0989f560a44e2c55_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1305 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\4e644aa26d4668a647d9dc62c9c98b46_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1305 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\5a24e495f22d6c1ef0a82e7782d4a8a9_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1305 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\5dbc6d95b2ff47a533806688fd34117d_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1305 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\5fd02a6b23562662a6cb0e471dfa39f9_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 77 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\63a0d44b192eab6dadb84b75f2149f50_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1305 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\6617fb65cc2e63c6c4d7f324a51726e6_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 77 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\1d10613f2ee966c84d6d08e3bb10dc13_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1305 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\4e59c873f40923ce700185cae19e8d67_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 77 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\77c6ac1113d8c12d29510857cf24887c_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 77 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\a0876bf21bd2d3fc57718d1034b04f7d_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1305 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\cb5711b693fca91e6716249549874fd1_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1305 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\6c680727dfac19a9df999734358e32e7_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1305 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\71515343ba2ad84049670f95b92dbcc6_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 77 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\72b12c26eddb5887ac5c650b877d69e2_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1305 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\731b1e3b8827140b2437f7d2d364abad_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 77 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\73a0a4df93e55407c2ab582ab0d31534_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 77 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\75dc40c0bd44c4b6c8d9233839b82cce_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1305 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\7850cd832470564bb798447238d0f5a1_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1305 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\7b214f26ea27b34de34b1caa21dac2b5_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1305 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\7c36cc5eab650472ee31eb657950667e_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1305 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\7d21f082ba5d6d1ab71cc19a74620fc8_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1305 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\7e6e9ddfcafb8126cc0e8389b15f5bdc_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1305 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\8282e8491eefafb505a6708815b870ac_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 77 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\85c29698354827f41950a6dd5d34dc36_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1305 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\8a50cac3f80ee2626f1af95ecf128b1e_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1305 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\8ccc8eafa87a08489b235008a203ab68_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1305 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\94d55ff7df0770e758efc28974ca9b02_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 77 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\956ad10d58b113cb1fcaa6fdc9e12fbc_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1305 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\9de385a8cc241d241afa81103f4e3352_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 77 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\a1078b3a38a3db2fa971e00633c1e270_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 77 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\a9fea6c2b04ea01f95420fba2de317c4_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1305 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\abc682d080ba323b7405de263ceedd61_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 77 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\ae5401eb2f82750f5f7b56389f6a2000_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 77 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\af613da282cd4b826ef8caa1a1f97f1c_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 77 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\b25d710d6334a5500bd8e9f06016e3a4_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 77 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\b82b69ef84927f9e283532c1b7f98e75_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 77 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\ba725f5e778faf6b8202241e8efaddb2_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1305 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\bce825ba9f2c21c73598fcdb672ca32e_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1305 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\bdf7b3761c6f7bdf4a2f5bbfa48dd1ea_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 77 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\c5a6327b3caef2bf2f1512aa3a658107_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 77 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\cad22f0cfb08f5ee78d507cfaddcd175_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 77 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\d2bd7e426526cf89736dbd99f7230c93_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1305 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\d5f31bab4b933e26ecfec30c9a2578e6_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1305 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\d8485f09a481470433d5ea96ac7440c3_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 77 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\d881cbbb913ddb4f4b0065f4a0ad7a77_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1305 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\e20ecd0f5458e729de49a695df2fad94_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1305 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\e21c346bfa45211cb639e6748de64787_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 77 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\e25f18cba290c1e7e3b595f8adb4a6b7_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1305 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\e325bc14d087a2dd00047475d2ea6f0b_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1305 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\e555bd8697dbb94d37e99032802a5e94_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1305 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\e60c399420b4bc2eb668c2ec82e9dc42_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 77 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\eb9b8498fafe1a064500d02b9031328a_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1305 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\eede0f6f2e71e48731f0bdccc694d9a7_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 77 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\f37a42650f2ec4427531b83ffbac45ea_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 77 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\f63e1a83ad35d2d00499eb47c50927cf_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1305 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\fc1e3851f429ea606d6ff1e01a5229f1_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 52 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\fcad562231fd1169ef17d25fb9b1e154_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 77 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18 0 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\000b42e96d09afcdf63d3ddf543246b4_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\00d9c42b52d204bc9aa112a82ddf7d39_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\00f38c23dafbcff664ed55c0d5206983_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\018b6eae123be07930b1128fad75e780_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\0209427ab6eb2d12ed27dfb320aaa5f0_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\028697626d931a3dadc2af27b1e29acb_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\0386f043889bced0a68ebdd17e9c5a60_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\050c6b37b2a158c4d2fb908e65d99528_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\05ca45fd6d214ab9cf6a79f31309adfb_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\0666c7c4431bf9597875e21872f9c850_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\082b89ba8486c0f32fd0eb0bdce06212_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\093406d23d3cda8c7a3ebe14ec51913f_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\0954cc647aca7d7d0e3b6a03bc919d51_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\098cfcc3485f74920393e9633a10f454_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\098f9c85ac85b3eb42b387b3cd6679fc_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\09d605c30e84a6393735e17a1f08ce52_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\0a9ffbad1919393e593226a004127cd5_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\0bba4d23d287958d284dbae55c80a441_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\0d6557f64385315df2bf8b51e41f0797_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\0dc84f417cd79202bb417e97e511cbc1_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\0fa6d93d9415ad519adfd09234df557f_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\112c5b94a205c885c0a3de671942bced_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\1142d7aeaf4242033dd6085c8fb95236_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\115b7df1cbda80fe5ee4582a96b2086d_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\02a29626fdd2b823d50324a0bc7939e3_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\0c65988d028b34539afec61b47edbba5_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\142f9c0033f01fd627ff92786e240208_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\1eee79fd85bb2a840645baba93f5a9dd_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\2745a9efbfbc8778e5006c6eda693bc8_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\310d393fbe9ae7ea4ee053478529a1d0_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\119c1a377c8c62dc17b066f7251e0e86_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\11a2b062bc4be91f18bc1eb4f88518b7_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\1270ce1b789d584cbb1b9f847ac98d37_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\12eb9eff6e6b88eac03d4d4823f47b42_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\12fd4459348c47cc2c5b685b6d2105d7_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\1386e232fe50cbfeecfd2c81201c45a3_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\152e29cd616437519c2221999497e68d_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\155907eb654d9d3c9153d612d30241c6_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\16403542cc9738c9946dd123cdf9e444_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\1671cf1ac4275f43e312731122c1fc4a_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\1778eef9b421ce15d5566b44165a7979_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\1838e04e6a4ce49a3118821cc969f3c7_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\1c5bf14ebe4991762fbd7bdde1bb153a_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\1d19d12b3fd49ec72904b6d7b027512b_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\1d694700c39e6a53f96ff972071ac607_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\1df755c48a017770dc73c91523b8420d_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\1e369f56f9718a6ae35dec3abf5cb87b_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\1eac9c7f0df32862cf64a3f111d440ff_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\1f7d892a6f9f81b2cbe8ad1a5db815dc_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\20087edeca749928d68c58fd2fb068e0_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\21891995768b98f68c7655e054721c94_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\21e5cc130b7e10a0cb08b8aebebc36ea_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\227c4d2ed9f80484844cc88efc526d27_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\22840d626ca167a282f9b65a80775a0f_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\2428e4ce85eadbdccdb27e5144b59510_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\242bbd42d7facbc3ae0ed1a423d9bae0_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\24404e275d016b6745775c22227f4feb_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\24bc456f3b0fbd2e3090c5ea25767a9d_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\263c1c20f70bee47f2f6e5d534ec00d8_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\273b6f8050d735370e2875324d152efc_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\2748d0ae1fff633bd2376af401e45b32_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\277f1e66b46bbdd68f425e9da0f6d16f_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\29bf7b94312dc8b2efdac53345839a4a_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\2abe9ecde293901f959c1698a2ee19f2_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\2b55b4475275fe3f3739db22ca702013_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\2c196ffa1849498eb9fbb319706e78a3_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\2c8c25a510cbdb1e90074ea1823396cb_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\2d02686a8c1ca4025c074672b85db174_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\2de994560af9ecab4520a2ec70550ec0_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\3003816724d35e6e6657d8ce766eee8d_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\309029022f23b5754f3b3c2bf15b5bba_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\30cddbd8b39674d1be1660e65feb666b_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\31297b2a8c2acd7854df801655e981f5_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\31f96ca0f6ebc9981256c8cc2459572a_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\323546e6d8c82323da7a636e22cf5dc8_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\324e0566f68ac9b5d8b05771c26b6855_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\326518c4e053a6ea5ae4d389809e5bbd_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\32cb42f24a14bf0f8632ef6b22621106_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\32e8b97e00bf2b93f041c9f3ffa1db14_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\3341a48e433100de9250c38dde860338_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\336098a78bce9fa7865e324d5b425f26_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\33cb7a313a40944ed2684c65fcda2ae7_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\34eb1f8f4eb73109436de2f8b91b6395_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\34ee69d729fcfbf7c4aad5a261a6686e_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\35bea52f922727a4159b2b96d450b65c_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\36155407510fbc7e5836de7e3cdce6e1_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\3627da60426c85d1da15c83b2c39c1b5_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\368e1ec10e3c7b5fdd90f949d121b2c9_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\3749a38d8a55d7dd0b347ef40c4bf4fd_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\3848be85452c3a4e7a7aa633fc1143a5_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\3868841b997c5eb8242c78ebcb5f63b0_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\386f35104c678ee63ac2b7dbed54c20e_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\38e8c918caa57d53579d22268d8d4ee1_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\3d15a589ad55b0d44230cc7d1e89be71_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\3f6a91f8a896ec54865308eb7bec028d_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\3f97b5bcf7ad655fc5bad6949e049eb2_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\41deb19743a0ad411c86d8eaf4dbfb99_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\42240d2a03366a4ca99783b39770153f_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\47996d66959160b273e09bea95de4f03_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\4821220ae064352faac130986c82ff0d_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\4a72384ed9dea6a7e1ead23a5109bef2_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\4a76f9303c909ac3fe5151ad549c082a_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\4b82ba3534bbfee2e1296c9dbd75f1ef_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\4c324a4cf1394c4bb90ce110b83e50c0_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\4c94ca07b3bf1742d4c26ed85857826c_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\4cc480b272c4a58827f926ae074f7cc3_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\4d2af19653231498786e4ec27d26b67d_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\4f7c21a2efb3f8e694d673081aca5590_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\517cbca02a6d17e2a203274de665e499_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\53418e1e88e93e1b4234f2ff210ebfb0_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\53db1aa8b1eaa59aaff0e568ea3baac0_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\54307fd1d0ac00760ce4cba470c263d7_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\55942328870c0633cb4b13287da3dc6c_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\55ce2df15d5c487f6345b6b9b50329e7_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\56dd03c2ce5e81f3d873461af0ab211f_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\5791956828074a0df01278ef64e3f281_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\57ea8f6d5747434db8e7a6bc939a4b79_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\583569b1360201c08b22368b754bc098_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\5964bb2b02ea929d3d1232d63b051cf8_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\5b68c8c3bfeff58f7b2a3c9abab8db12_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\5dd5b2fa27061ed54804a04460349f7b_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\5e0758e859e380783866a2931fcdd95b_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\5e665554ed3bdc7dee5924b91bcde4a7_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\5f07798e2aab8e3c8c1bc4160049d428_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\5f5cb973c7b89f647e72e17ae5efbf2a_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\60048ab75e065db838cd39e0fc376965_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\607e8a484ab179b0e4c5764eb20f9de6_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\60c10df832cd4ae00799c1b9fa7657a5_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\618e2d7188eb816440ba4a1f7cc880ac_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\61a32a677a5e5569e5e6ba5c61835514_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\61a4ab2993b52a2a5904f26e3ebb8ae5_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\6210a2414d2091811319bf850edcea35_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\62a45886e06c7d046ea8b819bec0598a_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 45 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\62e39a9950fdab4e0e0d71d52949f5f4_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\63de350d0217113cc5c7a66ea928b067_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\66f8e2468ed3cdc46ae0bf84f7c0500b_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\673bbf4059b305b1fccf0fdbca2cdb4f_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\676d49c362d5cb5cf44a7fc0ccc2fa29_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\68e9a1816f851cc7dc063aa9f17fd0b0_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\6921ad06af26197b9dcc52c89f7ef6b1_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\6b25dae14f51b83632b0a16c395bbbba_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\6be60fd3b37facae250dbc86b9f17eb9_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\6c472b80d3cc4f92be88601df57b93ac_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\6d14e4b1d8ca773bab785d1be032546e_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 47 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\6fedf6e5691efe857a31478ea5d2006d_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\70e3e680e7df39601cdd3af700934f42_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\7271f84a2d63acfd4247fb7206371385_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\72c8fb553e2d59dfc8b4f22d614c8750_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\73181c2501d01b3dcded3405328321a2_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\7442508981b436956b297583f6c54104_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\35409e3509f790b5fadacc5ef0dafbda_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\410fa1ec8a666a1acc59b0b8195027da_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\4fde83c7e1f3774fdcea5e18ee13975a_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\5bb3b524e410f40453fd4537642a34a9_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\622dfe861d87906e5a3d0acdcf9716d1_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\6e991195cbf4c6fcc1cea2bea01174b1_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\754a7280f4f33ec3bfbb6899a5de36c0_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\75b703602d0d152a6b97d51cd472c348_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\76f54eeda0b152e767e446027742a113_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\77e50834f4b00e67609bcb9c0fd526d1_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\78628be7916dfbbdcc4e0755b76a814e_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\78dc6182a2fd3e1b4956cf18875ebbc1_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\7ae641024b3d0bcc4b25a31eaa174550_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\7b4746750dee66d89a3ff1bf3063521f_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\7c2e8f5c2ef6f7da584601a0ac72ce7f_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\7c7fc130d9872e763955ad63559890c6_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\7cd9b145fd045e6cbc0e65bc4f62ef55_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\7d134b512886819e69d23bc3e9a964a4_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\7d75a3982955b5ff3a6abd013c039f19_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\7d7a8edf24e25b9b5afd278fe71f2466_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\7db3a3a2ee4d6ce11f354f93494e25a9_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\7f609d23740663427a323693f88bd10d_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\7fa6de15d04e5d07befba89a4a12dedd_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\7ff109e75653c7956cc4741c310ab1a6_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\800e2c151b0af10abfb4451d5987d6c8_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\802d0e794db81f3e4be8ff0899c9c4b0_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\81cbb2f85f6ed804e43b788ab06eaba4_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\82170cbad6529806a9352431f42ed9a1_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\82171d8eace2505c0da54664f592b2fa_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\82a75891fc4cbe5e173edb0e1098f8e4_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\8308017948f132c015963d4848e0d76f_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\831a5d62d735c94cd2b50c5a058637b2_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\8442e918db0036e9f0dc233afcaeed92_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\85438726335fad46e4e27771f4f7d363_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\8619a015b39829ffcceda5f1e9aacd81_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\864dfad64f23e0240a80b522c38fe7e5_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\86d221d33b613e913c9dc6b259fb4cc9_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\88a11b4142e1516280560f62a76ce5b2_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\89b900c5d9a257fff8b661db7ad32e28_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\8bf67c07d431b3e7e14804147d59b7a5_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\8d76241491a347c9731943e005dcdaf1_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\8dea36f7790878ce2320fe319e269619_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\8f2f8e071e3a627d9b876fa3a48b0e1a_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\8f6898c1007b80dd05ba823ec75ffa85_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\8f71098770f72c7a67cd8f1151619865_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 54 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\9054cdf08330aab4c53d1580be1bcfe4_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\909f699f6c266c2f7f1d23ab41059a61_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\9127c0f580daeca87fc6e3088defabb6_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\92a92823dde9dba165a12885a10805c4_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\92ca902f06122bf3972873fcf4d0510d_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\93f136b11dc7b7c40e3576c93f2f4d9c_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\94e1b64d9e83f84448c257c10e2dbd78_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\95f3dff7c85bcbe05c66c19a4ccddf3b_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\9613c157a5f9105e91202e4ab893e044_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\9624deaec1435a8ce0207e6b83dcbebb_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\973d85211269d6add6811f49b572de26_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\97dc356cebb7d61ecbcc448e011ce66e_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\98b8acaaf9a2c4883265bb29ecadb378_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\9996e98d7a8e464e646143da8fb84ab9_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\99f8e41d668570d54f218c7d6675267a_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\9a09831ce313be5d62c7c9e736e7b8fa_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\9a7607c8d83dcba84febe1160e8d0a8f_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\9c7da449af14610d30d2a4a52f5de330_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\9d1b5047917f55f5261a8700d19d8d86_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\9d67d9d613d73e1754fe120a08408ce6_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\9db949848b281d93eba463a10feb9c24_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\9f536178c7400d4b34992fd8b88d78f9_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\9fd8f5fb3b655a60c17917734c8d928a_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\a1d14fbb44823018be7294589764861e_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\a1e8be95995b7b506e0c41dbf0f2b908_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\a242fc602d4a79168bd5a655b45934e1_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\a2b27787f8dddd4f9908e35d692b1278_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\a46d6fa91383bbc4710b0b03322a2f69_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\a4f58f9a2617e58b971fede3136501c2_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\a572bf78501da9e62b484d5d744e15d1_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\a65bd8fd48ee250be39bbf000ab83359_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\a6a7ab7493edd04f791c508073fe9472_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\a7bb025e7e88562b6a9cb330e89a01c2_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\7a24c8c0c41ac33edae57ad435963eec_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\8003601468a500cd9af7b20b6f1ceeb2_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\86627ba866fd95c7f29ebae9b6c06c72_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\926d3c1298401b9945fb5d0dd29dec21_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\9a020c1bff517c624aa0cb7c6feff820_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\a2f326ca9addef08a9b49cd0468051e7_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\a7e35ea92f17613eb2b2e373528336bc_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\a89caceca2bdcd1d32e606e90a63a12e_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\a9140c85ff9365106e6a45e709bd6f5c_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\a9761fd0be0d6e2200d9bc62c0a542e0_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\ab475b4f414a8270ac0522578f64857f_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\ab4ba518864bf960fb3244cdf7bc78e7_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\abb399d10d081e77225aa814a087f65c_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\abe8ed6ea68ab66e8301e480ebec335e_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\ac8a62a55f0142c8457d001b4a27aef9_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\ad32e75ae845baa0ee84aa6d422f2348_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\addf9c663866a310fcba8a29d2f80044_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\ae32a1a4943b05b60b24c4c48a490b85_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\ae8cd8961b2eb77eca07ba04769f0135_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\af1786190a6e585eead084e2485e6f7d_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\b0a62b5a0f875106cc85b8c0d323de98_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\b3cf837eca757760267cc645b183577f_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\b3fcd4e595f10ec5edf96ccbdbeb9d0f_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\b4d994cc08d854414c4f332b6db5d318_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\b55984a1caacd751b0b10db2f4e61f4a_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\b59b036715e4140c8e4447c0f2fb506b_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\b5e9b51b5ed4cdaea6795c4615dad4de_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\b7366252d951777693ea01ee8f6fdfbf_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\b809f75a0bd3d606f301080e94c8fe0e_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\b8277775bffe44b38cad640491c1a7e8_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\b8feeb0a18985b34eff6688738eeeb51_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\b98a9214af4d70fe94701b6998d922d2_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\b9c348a4dd73ef365e52e4065a757356_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\b9ef25a58499f49f44f7b86db16b18bf_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\bb55cb9bb33e12f1cf3a400672810326_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\bb6b36f04e0d26fe5824be5801b8db9b_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\bec66dcabd34575bda1169a594a935f7_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\bf97e6fdf064359203136ecbb48fbe37_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\c0a9f328d94b9db2e228717de4933af3_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\c15cbda44d389f01fcdf54ee31b1a39c_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\c4562262b64a9f3ab49be753319d3bcf_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\c54bbff0a6a284dee25f70b9ff039825_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\c5d0a17959db97850c7f3b4a0b302df0_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\c6015c58c3e8f63ed31d3d83d39854ee_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\c62c5796f7881468ae880ba583799275_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\c65dd1d9978f9060dea73831435b3f55_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\c6924f790726a20860bc7f8363dccdce_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\c692a8e64d0434aff4aad1f457bf0833_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\c78896bc0bee16ed759656f1c8669ca0_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\c8e59f84097c33b27609253b88a813ac_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\ca8ca2565602d5f1e4769075ae44e72d_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\cb70b7541e36cd528d85a731f1cbe3fc_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\cb9f9b40fb72dad63511722a3e1c7168_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\cbf082456d588da00882f8f81d3e446a_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\cc44d267bdc8978a01cbaa9217438b6e_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\cc9e55cb86a1edfc0bbe04a2befb3db3_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\ccb97d2046c0c810df9e040bf6f059f2_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\cd8ce6882f504e722f83748b5571271d_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\cd9b7fda3142a8e2b2e4aea0f288cd44_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\cdf4b674754fb600510b3d3f3792b0a3_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\d03e3121affc0665d0bd7d1d4a65e254_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\d099dfba6afac790387dd8a01345ab65_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\d0bd18b33319d03661f67887844e3c72_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\d1df9181d86252381c8b8af5a142dd7f_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\d210d259f449126992eaa206823aeeec_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\d24a03bd4c548c1968158330faff50bd_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\d3a373368a1d61a058f8d1ee373b85a9_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\d42cc0c3858a58db2db37658219e6400_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 893 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\d47489a70d420616490432a3d0466fc0_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\d4c0731e54c079070eda2abc8ebd020c_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\d5838f77898c891d5ab819631d7afb0c_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\d5ba19e121c9e1a78e43ba6ad63c837b_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\d6bc46bafb559febe7d387618246d298_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\d783d75aa702808e497586cf4e1c0b74_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\d93775aff46bd1cabb5341e5fd82ae96_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\d9cdd5651950f207c2298b3771b15f6f_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\d9d40168238137910d5c112ef8102c3c_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\dba12b32e34ec7f093b3f07945d58e2d_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\aba4a653b496b31e9213fc66251a8479_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\b5201703cd875d2900fe876178f5768c_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\bbfc9d1be506761f32a6f1d7832fd751_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\c6f2408596046621afb67d870886f08f_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\ce850911a3dda6033d0f448a5cbf874b_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\d622aaa084496e1d9d8a24f3c51eef60_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\ddc7c1acc433a5c59ce665004321818d_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\e63a512aa71c0a063c2b8b8b64e7f156_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\ee8cc76abdda94f65008180c58d57df6_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\f4772e6e0220c2a99798b4a59922b23f_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\dc0edc307b83eee946fb82aed15ebbac_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\dc0ff57d540a9f03fa31d3ef841ae827_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\dc20f685f59391a634ea8deba31a5834_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\dc989cee0b6cf8bc65f67e8bfb1f921e_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\dd1ae967c7b6a220fa38752e4e944537_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\dd4aa37be44fffd9c3383b694465e3d4_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\de1d0ebee9e9817b3556856acc8a2e3d_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\dfc2fc442d7390ab3b14526b18238663_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\dfc31b33a2eaf6705e59dabc2007dd43_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\dfcf6c97f5a2a9592e557e3d597fb2c3_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\dfd0edac581ca124caf8173a61926044_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\e0e9ca9e1ceb0418cbd53ca3b5546551_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\e1646849cd0c2a1ad8a1bb17b32ccf7c_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\e26a46937d2f0441900f33358144e951_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\e31aa44acef5bf97169abb8eb1155b55_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\e40e744eeefc169ccde265ead7516234_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\e429a1d6d4edb17b47dbc4b43d6efc43_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\e53dc4daccf861f6128271171b6a2136_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\e664e66b745af030ca6fda67357645a6_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\e68af571ac2e2410b9270468a9891a89_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\e73fe0d2dd986438cc3eb28cde3694a4_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\e7463a3bb96d57fd5a34980a810d75b7_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\e7ae638252d6919850c7bce950631954_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\e8647b3b919f3da565627de8547d75c0_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\e8b14950129b0ead8cb50da25e655b7f_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\ea3aea13ed38c9db32b7fed800c91b59_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\ec29ccf8bd5a7f21ae079aa907a9005a_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\ec40bd9051ef9e84b07b88e54d4ba573_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\ece571cd0be97825a68f10b6877376b7_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\ed2e99041efd32114c6cc73b8a418f0f_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\eefddf2d168e544f3d55379c3ebedd21_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\ef34555207506dbb7b0cec334a940207_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\ef4ef7cee2393128b9b81031eee809f8_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\f08504f127c66de609e6b42a0a97c779_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\f0c66157e861d31041f9b06c51492bd5_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\f20ac7eef155a17db4343296fe8d27e3_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\f2431d63bedb73609187892017372897_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\f25234c2056f701bb2fa575fd83ce8c5_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\f2f5082895d618ed6fa3957bac9b1e06_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\f353fc5ae8479d45452912011ea53bd5_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\f432c76ebfb39c5f55bb2692d59af39f_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\f453d47eab12ce7017271e0b75b56ee3_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\f4f268ff7c1e7adf9bc4bc242b7dc666_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\f5a44cc5fef6c5f07eb0a8f957474ace_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\f5bb1dc3f9cc4b23afba3d402afda7d9_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\f64fdbaabc358abb7fedb41ea1f2664f_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\f75b965e8ec7c397d34e0deedc780ad9_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\f774a2ba20d18abc377b1998ab351224_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\f784e87b779a983d0a33bb3b1ef8fa82_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\f8388c163e4b443b87ac2ed6481b76ee_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\fa0b82ac37abd5bd4dbd2e354901f412_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\fb91dede2cd63c277ee916147585d61b_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\fb93953756f285c2c4f4eb32569c60c1_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\fbe550c14a0d4a104a7d5e1e817cb130_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\fc7de783986de0c7075c1e0867fb9d01_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\fca20260c5f35599ced7aa4fce932de9_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\fdba91e981b515d2db5442d762ea1d39_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\fdc8957045c44450a96686ed0567a75c_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\febbdcfc0fc90a36af32c44241c2f950_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\ffbc9ff8e746635ffda23a5d7a8b6afc_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
    File C:\RRbackups\Q 0 bytes
    File C:\RRbackups\Q\0 0 bytes
    File C:\RRbackups\Q\0\Data0 50003968 bytes
    File C:\RRbackups\Q\0\Data1 50003968 bytes
    File C:\RRbackups\Q\0\Data2 50003968 bytes
    File C:\RRbackups\Q\0\Data3 36087695 bytes
    File C:\RRbackups\Q\0\dats 0 bytes
    File C:\RRbackups\Q\0\EFSFile 0 bytes
    File C:\RRbackups\Q\0\HashFile 5244 bytes
    File C:\RRbackups\Q\0\Info 756 bytes
    File C:\RRbackups\Q\0\TOCFile 533140 bytes
    File C:\RRbackups\Q\1 0 bytes
    File C:\RRbackups\Q\1\Data0 22903 bytes
    File C:\RRbackups\Q\1\dats 0 bytes
    File C:\RRbackups\Q\1\EFSFile 0 bytes
    File C:\RRbackups\Q\1\HashFile 5250 bytes
    File C:\RRbackups\Q\1\Info 756 bytes
    File C:\RRbackups\Q\1\TOCFile 533750 bytes
    File C:\RRbackups\S 0 bytes
    File C:\RRbackups\S\0 0 bytes
    File C:\RRbackups\S\0\Data0 50003968 bytes
    File C:\RRbackups\S\0\Data1 50003968 bytes
    File C:\RRbackups\S\0\Data10 50003968 bytes
    File C:\RRbackups\S\0\Data11 50003968 bytes
    File C:\RRbackups\S\0\Data12 1152832 bytes
    File C:\RRbackups\S\0\Data2 50003968 bytes
    File C:\RRbackups\S\0\Data3 50003968 bytes
    File C:\RRbackups\S\0\Data4 50003968 bytes
    File C:\RRbackups\S\0\Data5 50003968 bytes
    File C:\RRbackups\S\0\Data6 50003968 bytes
    File C:\RRbackups\S\0\Data7 50003968 bytes
    File C:\RRbackups\S\0\Data8 50003968 bytes
    File C:\RRbackups\S\0\Data9 50003968 bytes
    File C:\RRbackups\S\0\dats 0 bytes
    File C:\RRbackups\S\0\EFSFile 0 bytes
    File C:\RRbackups\S\0\HashFile 55530 bytes
    File C:\RRbackups\S\0\Info 756 bytes
    File C:\RRbackups\S\0\TOCFile 5645550 bytes
    File C:\RRbackups\S\1 0 bytes
    File C:\RRbackups\S\1\Data0 70058 bytes
    File C:\RRbackups\S\1\dats 0 bytes
    File C:\RRbackups\S\1\EFSFile 0 bytes
    File C:\RRbackups\S\1\HashFile 55536 bytes
    File C:\RRbackups\S\1\Info 756 bytes
    File C:\RRbackups\S\1\TOCFile 5646160 bytes
    File C:\RRbackups\SIS 0 bytes
    File C:\RRbackups\SIS\C 0 bytes
    File C:\RRbackups\SIS\C\0 0 bytes
    File C:\RRbackups\SIS\C\0\Data0 25613816 bytes
    File C:\RRbackups\SIS\C\0\Data1 121004 bytes
    File C:\RRbackups\SIS\C\0\Data2 24425 bytes
    File C:\RRbackups\SIS\C\0\Data3 29185 bytes
    File C:\RRbackups\SIS\C\0\Data4 8531 bytes
    File C:\RRbackups\SIS\C\0\Data5 7987544 bytes
    File C:\RRbackups\SIS\C\0\HashFile 36 bytes
    File C:\RRbackups\SIS\C\0\TOCFile 3660 bytes
    File C:\RRbackups\SIS\Q 0 bytes
    File C:\RRbackups\SIS\Q\0 0 bytes
    File C:\RRbackups\SIS\S 0 bytes
    File C:\RRbackups\SIS\S\0 0 bytes

    ---- EOF - GMER 1.0.15 ----


    From MBERcheck:

    MBRCheck, version 1.2.3
    (c) 2010, AD

    Command-line:
    Windows Version: Windows Vista Business Edition
    Windows Information: Service Pack 2 (build 6002), 64-bit
    Base Board Manufacturer: LENOVO
    BIOS Manufacturer: LENOVO
    System Manufacturer: LENOVO
    System Product Name: 7465CTO
    Logical Drives Mask: 0x0005000c

    Kernel Drivers (total 177):
    0x02A15000 \SystemRoot\system32\ntoskrnl.exe
    0x02F2D000 \SystemRoot\system32\hal.dll
    0x0060A000 \SystemRoot\system32\kdcom.dll
    0x00614000 \SystemRoot\system32\mcupdate_GenuineIntel.dll
    0x0064F000 \SystemRoot\system32\PSHED.dll
    0x00663000 \SystemRoot\system32\CLFS.SYS
    0x006C0000 \SystemRoot\system32\CI.dll
    0x00800000 \SystemRoot\system32\drivers\Wdf01000.sys
    0x008DA000 \SystemRoot\system32\drivers\WDFLDR.SYS
    0x008E8000 \SystemRoot\system32\drivers\acpi.sys
    0x0093E000 \SystemRoot\system32\drivers\WMILIB.SYS
    0x00947000 \SystemRoot\system32\drivers\msisadrv.sys
    0x00951000 \SystemRoot\system32\drivers\pci.sys
    0x00981000 \SystemRoot\System32\drivers\partmgr.sys
    0x00996000 \SystemRoot\system32\DRIVERS\compbatt.sys
    0x0099A000 \SystemRoot\system32\DRIVERS\BATTC.SYS
    0x009A6000 \SystemRoot\system32\drivers\volmgr.sys
    0x00772000 \SystemRoot\System32\drivers\volmgrx.sys
    0x009BA000 \SystemRoot\system32\drivers\pciide.sys
    0x009C1000 \SystemRoot\system32\drivers\PCIIDEX.SYS
    0x009D1000 \SystemRoot\System32\drivers\mountmgr.sys
    0x00A07000 \SystemRoot\system32\DRIVERS\iaStor.sys
    0x00B24000 \SystemRoot\system32\drivers\atapi.sys
    0x00B2C000 \SystemRoot\system32\drivers\ataport.SYS
    0x00B50000 \SystemRoot\system32\drivers\msahci.sys
    0x00B5A000 \SystemRoot\system32\drivers\fltmgr.sys
    0x00BA1000 \SystemRoot\system32\drivers\fileinfo.sys
    0x00BB5000 \SystemRoot\System32\Drivers\DRVECDB.SYS
    0x00BD2000 \SystemRoot\System32\Drivers\PxHlpa64.sys
    0x00C0C000 \SystemRoot\System32\Drivers\ksecdd.sys
    0x00E0B000 \SystemRoot\system32\drivers\ndis.sys
    0x00C93000 \SystemRoot\system32\drivers\msrpc.sys
    0x00CE3000 \SystemRoot\system32\drivers\NETIO.SYS
    0x01009000 \SystemRoot\System32\drivers\tcpip.sys
    0x0117F000 \SystemRoot\System32\drivers\fwpkclnt.sys
    0x0120C000 \SystemRoot\System32\Drivers\Ntfs.sys
    0x0138C000 \SystemRoot\system32\drivers\volsnap.sys
    0x013D0000 \SystemRoot\System32\DRIVERS\ApsHM64.sys
    0x013DA000 \SystemRoot\System32\Drivers\spldr.sys
    0x011AB000 \SystemRoot\System32\DRIVERS\Apsx64.sys
    0x013E2000 \SystemRoot\System32\Drivers\mup.sys
    0x011CF000 \SystemRoot\System32\drivers\ecache.sys
    0x00FCE000 \SystemRoot\system32\drivers\disk.sys
    0x00D3C000 \SystemRoot\system32\drivers\CLASSPNP.SYS
    0x013F4000 \SystemRoot\system32\drivers\crcdisk.sys
    0x02328000 \SystemRoot\system32\DRIVERS\tunnel.sys
    0x02335000 \SystemRoot\system32\DRIVERS\tunmp.sys
    0x0233E000 \SystemRoot\system32\DRIVERS\intelppm.sys
    0x02404000 \SystemRoot\system32\DRIVERS\igdkmd64.sys
    0x02C0B000 \SystemRoot\System32\drivers\dxgkrnl.sys
    0x02CEE000 \SystemRoot\System32\drivers\watchdog.sys
    0x02CFE000 \SystemRoot\system32\DRIVERS\HECIx64.sys
    0x02D0F000 \SystemRoot\system32\DRIVERS\serial.sys
    0x02D2C000 \SystemRoot\system32\DRIVERS\serenum.sys
    0x02D38000 \SystemRoot\system32\DRIVERS\e1y60x64.sys
    0x02D88000 \SystemRoot\system32\DRIVERS\usbuhci.sys
    0x02D94000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
    0x02DDA000 \SystemRoot\system32\DRIVERS\usbehci.sys
    0x02E05000 \SystemRoot\system32\DRIVERS\HDAudBus.sys
    0x0300A000 \SystemRoot\system32\DRIVERS\NETw5v64.sys
    0x034AF000 \SystemRoot\system32\DRIVERS\i8042prt.sys
    0x034C5000 \SystemRoot\system32\DRIVERS\kbdclass.sys
    0x034D3000 \SystemRoot\system32\DRIVERS\tp4track.sys
    0x034DF000 \SystemRoot\system32\DRIVERS\mouclass.sys
    0x034EB000 \SystemRoot\system32\drivers\tpm.sys
    0x034FB000 \SystemRoot\system32\DRIVERS\CmBatt.sys
    0x03500000 \SystemRoot\system32\DRIVERS\ibmpmdrv.sys
    0x0350B000 \SystemRoot\System32\Drivers\DLACDBHE.SYS
    0x0350E000 \SystemRoot\system32\DRIVERS\cdrom.sys
    0x0352A000 \SystemRoot\system32\DRIVERS\GEARAspiWDM.sys
    0x03537000 \SystemRoot\system32\DRIVERS\wmiacpi.sys
    0x03540000 \SystemRoot\system32\DRIVERS\msiscsi.sys
    0x03579000 \SystemRoot\system32\DRIVERS\storport.sys
    0x035D6000 \SystemRoot\system32\DRIVERS\TDI.SYS
    0x02EF2000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
    0x02F15000 \SystemRoot\system32\DRIVERS\mux.sys
    0x035E3000 \SystemRoot\system32\DRIVERS\ndistapi.sys
    0x02F94000 \SystemRoot\system32\DRIVERS\ndiswan.sys
    0x035EF000 \SystemRoot\system32\DRIVERS\raspppoe.sys
    0x02FC5000 \SystemRoot\system32\DRIVERS\raspptp.sys
    0x02FE3000 \SystemRoot\system32\DRIVERS\rassstp.sys
    0x02351000 \SystemRoot\system32\DRIVERS\rdpdr.sys
    0x02DEB000 \SystemRoot\system32\DRIVERS\termdd.sys
    0x02B91000 \SystemRoot\system32\DRIVERS\psadd.sys
    0x02B9D000 \SystemRoot\system32\DRIVERS\Tvti2c.sys
    0x03000000 \SystemRoot\system32\DRIVERS\swenum.sys
    0x02BAB000 \SystemRoot\system32\DRIVERS\ks.sys
    0x02C00000 \SystemRoot\system32\DRIVERS\mssmbios.sys
    0x02BDF000 \SystemRoot\system32\DRIVERS\umbus.sys
    0x00D68000 \SystemRoot\system32\DRIVERS\usbhub.sys
    0x023EB000 \SystemRoot\System32\Drivers\NDProxy.SYS
    0x04A0D000 \SystemRoot\system32\drivers\CHDRT64.sys
    0x04AAC000 \SystemRoot\system32\drivers\portcls.sys
    0x04AE7000 \SystemRoot\system32\drivers\drmk.sys
    0x04B0A000 \SystemRoot\system32\drivers\ksthunk.sys
    0x04B10000 \SystemRoot\system32\DRIVERS\CAXHWAZL.sys
    0x04C0F000 \SystemRoot\system32\DRIVERS\CAX_DPV.sys
    0x04E0F000 \SystemRoot\system32\DRIVERS\CAX_CNXT.sys
    0x04EDA000 \SystemRoot\system32\drivers\modem.sys
    0x04EFC000 \SystemRoot\System32\Drivers\Fs_Rec.SYS
    0x04F06000 \SystemRoot\System32\Drivers\Null.SYS
    0x04F0F000 \SystemRoot\System32\Drivers\DLARTL_E.SYS
    0x04F22000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS
    0x04F2A000 \SystemRoot\System32\drivers\vga.sys
    0x04F38000 \SystemRoot\System32\drivers\VIDEOPRT.SYS
    0x04F5D000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
    0x04F66000 \SystemRoot\system32\drivers\rdpencdd.sys
    0x04F6F000 \SystemRoot\System32\Drivers\Msfs.SYS
    0x04F7A000 \SystemRoot\System32\Drivers\Npfs.SYS
    0x04F8B000 \SystemRoot\System32\DRIVERS\rasacd.sys
    0x04F94000 \SystemRoot\system32\DRIVERS\tdx.sys
    0x04FB1000 \SystemRoot\system32\DRIVERS\smb.sys
    0x04D83000 \SystemRoot\system32\drivers\afd.sys
    0x04B63000 \SystemRoot\System32\DRIVERS\netbt.sys
    0x04FCC000 \SystemRoot\system32\DRIVERS\pacer.sys
    0x04FEA000 \SystemRoot\system32\DRIVERS\netbios.sys
    0x04BA7000 \SystemRoot\system32\DRIVERS\wanarp.sys
    0x04FF9000 \SystemRoot\System32\drivers\Tppwr64v.sys
    0x04E00000 \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS
    0x04EE9000 \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS
    0x04BC2000 \SystemRoot\system32\DRIVERS\usbccgp.sys
    0x04EF3000 \SystemRoot\system32\DRIVERS\USBD.SYS
    0x00DB0000 \SystemRoot\system32\DRIVERS\rdbss.sys
    0x04BDE000 \SystemRoot\system32\DRIVERS\5U875.sys
    0x04DEE000 \SystemRoot\system32\DRIVERS\STREAM.SYS
    0x04C00000 \SystemRoot\system32\drivers\nsiproxy.sys
    0x04EF5000 \SystemRoot\system32\DRIVERS\smiifx64.sys
    0x05002000 \SystemRoot\system32\drivers\csc.sys
    0x05078000 \SystemRoot\System32\Drivers\dfsc.sys
    0x05095000 \SystemRoot\system32\DRIVERS\avipbb.sys
    0x050B7000 \SystemRoot\system32\DRIVERS\hidusb.sys
    0x050C0000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS
    0x050D2000 \SystemRoot\system32\DRIVERS\mouhid.sys
    0x050DD000 \SystemRoot\system32\DRIVERS\kbdhid.sys
    0x050E8000 \SystemRoot\System32\Drivers\crashdmp.sys
    0x02200000 \SystemRoot\System32\Drivers\dump_iaStor.sys
    0x00000000 \SystemRoot\System32\win32k.sys
    0x050F6000 \SystemRoot\System32\drivers\Dxapi.sys
    0x05102000 \SystemRoot\system32\DRIVERS\monitor.sys
    0x00410000 \SystemRoot\System32\TSDDD.dll
    0x00690000 \SystemRoot\System32\cdd.dll
    0x05115000 \SystemRoot\system32\drivers\luafv.sys
    0x05137000 \SystemRoot\system32\DRIVERS\avgntflt.sys
    0x05154000 \SystemRoot\system32\DRIVERS\tvtfilter.sys
    0x05163000 \SystemRoot\System32\Drivers\DRVEDDM.SYS
    0x05171000 \SystemRoot\System32\DLA\DLADResE.SYS
    0x05172000 \SystemRoot\System32\DLA\DLAIFS_E.SYS
    0x05194000 \SystemRoot\System32\DLA\DLAOPIOE.SYS
    0x0519B000 \SystemRoot\System32\DLA\DLAPoolE.SYS
    0x0519E000 \SystemRoot\System32\DLA\DLABMFSE.SYS
    0x051A8000 \SystemRoot\System32\DLA\DLABOIOE.SYS
    0x051B1000 \SystemRoot\System32\DLA\DLAUDFAE.SYS
    0x051D1000 \SystemRoot\System32\DLA\DLAUDF_E.SYS
    0x1580A000 \SystemRoot\system32\drivers\spsys.sys
    0x158A4000 \SystemRoot\system32\DRIVERS\irda.sys
    0x158C7000 \SystemRoot\system32\DRIVERS\lltdio.sys
    0x158DB000 \SystemRoot\system32\DRIVERS\nwifi.sys
    0x1590F000 \SystemRoot\system32\DRIVERS\ndisuio.sys
    0x1591A000 \SystemRoot\system32\DRIVERS\rspndr.sys
    0x15932000 \SystemRoot\system32\drivers\HTTP.sys
    0x159D5000 \SystemRoot\System32\DRIVERS\srvnet.sys
    0x00FE2000 \SystemRoot\system32\DRIVERS\bowser.sys
    0x00BDE000 \SystemRoot\System32\drivers\mpsdrv.sys
    0x007D8000 \SystemRoot\system32\drivers\mrxdav.sys
    0x15E0B000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
    0x15E34000 \SystemRoot\system32\DRIVERS\mrxsmb10.sys
    0x15E7D000 \SystemRoot\system32\DRIVERS\mrxsmb20.sys
    0x15E9C000 \SystemRoot\System32\DRIVERS\srv2.sys
    0x15ECE000 \SystemRoot\System32\DRIVERS\srv.sys
    0x15F61000 \SystemRoot\system32\DRIVERS\mdmxsdk.sys
    0x1640C000 \SystemRoot\system32\drivers\peauth.sys
    0x164C2000 \SystemRoot\System32\Drivers\secdrv.SYS
    0x164CD000 \SystemRoot\System32\drivers\tcpipreg.sys
    0x164DD000 \SystemRoot\system32\DRIVERS\xaudio64.sys
    0x164E5000 \SystemRoot\system32\DRIVERS\cdfs.sys
    0x16501000 \??\C:\Windows\system32\drivers\mbam.sys
    0x76F80000 \Windows\System32\ntdll.dll

    Processes (total 122):
    0 System Idle Process
    4 System
    496 C:\Windows\System32\smss.exe
    628 csrss.exe
    664 C:\Windows\System32\wininit.exe
    684 csrss.exe
    720 C:\Windows\System32\services.exe
    732 C:\Windows\System32\lsass.exe
    740 C:\Windows\System32\lsm.exe
    820 C:\Windows\System32\winlogon.exe
    928 C:\Windows\System32\svchost.exe
    1012 C:\Windows\System32\ibmpmsvc.exe
    376 C:\Windows\System32\svchost.exe
    688 C:\Windows\System32\svchost.exe
    736 C:\Windows\System32\svchost.exe
    1036 C:\Windows\System32\svchost.exe
    1100 C:\Windows\System32\audiodg.exe
    1124 C:\Windows\System32\svchost.exe
    1180 C:\Windows\System32\SLsvc.exe
    1220 C:\Windows\System32\svchost.exe
    1332 C:\Windows\System32\svchost.exe
    1456 C:\Windows\System32\wlanext.exe
    1584 C:\Windows\System32\spoolsv.exe
    1608 C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
    1624 C:\Windows\System32\svchost.exe
    1820 C:\Program Files\Lenovo\HOTKEY\TPHKSVC.exe
    1868 C:\Program Files\SUPERAntiSpyware\SASCore64.exe
    1880 C:\Program Files (x86)\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
    1932 C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
    1948 C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    1972 C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
    1996 C:\Program Files (x86)\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
    2016 C:\Program Files (x86)\Bonjour\mDNSResponder.exe
    2040 C:\Program Files\Intel\WiFi\bin\EvtEng.exe
    1736 C:\Program Files (x86)\Seagate\SeagateManager\Sync\FreeAgentService .exe
    1048 C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe
    2160 C:\Program Files (x86)\Intel\AMT\LMS.exe
    2184 C:\Windows\System32\svchost.exe
    2208 C:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.exe
    2240 C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
    2376 C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe
    2416 C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
    2464 C:\Windows\System32\svchost.exe
    2516 C:\Program Files (x86)\Common Files\Lenovo\tvt_reg_monitor_svc.exe
    2528 C:\Windows\System32\TPHDEXLG64.exe
    2552 C:\Program Files (x86)\Lenovo\Client Security Solution\tvttcsd.exe
    2564 C:\Program Files (x86)\Lenovo\Rescue and Recovery\rrpservice.exe
    2580 C:\Program Files (x86)\Lenovo\Rescue and Recovery\rrservice.exe
    2608 C:\Program Files (x86)\Common Files\Lenovo\Scheduler\tvtsched.exe
    2696 C:\Program Files (x86)\Common Files\Intel\Privacy Icon\UNS\UNS.exe
    2808 C:\Windows\System32\svchost.exe
    792 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
    2384 C:\Windows\System32\SearchIndexer.exe
    2332 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
    2900 C:\Windows\System32\drivers\XAudio64.exe
    2308 WmiPrvSE.exe
    3308 C:\Windows\System32\taskeng.exe
    3392 C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe
    3420 C:\Windows\System32\dwm.exe
    3472 C:\Windows\explorer.exe
    3560 C:\Program Files (x86)\ThinkPad\ConnectUtilities\AcSvc.exe
    3772 C:\Program Files (x86)\Lenovo\System Update\SUService.exe
    3932 C:\Program Files (x86)\ThinkPad\ConnectUtilities\SvcGuiHlpr.exe
    4072 C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
    3684 WmiPrvSE.exe
    4592 C:\Program Files\Lenovo\TrackPoint\tp4serv.exe
    4612 C:\Program Files (x86)\Common Files\Intel\Privacy Icon\PrivacyIconClient.exe
    4620 C:\Windows\System32\taskeng.exe
    4636 C:\Windows\System32\TpShocks.exe
    4648 C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe
    4704 C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe
    4728 C:\Program Files\Lenovo\HOTKEY\tpfnf6r.exe
    4780 C:\Windows\System32\igfxtray.exe
    4816 C:\Windows\System32\hkcmd.exe
    4824 C:\Windows\System32\igfxpers.exe
    4836 C:\Program Files\Java\jre6\bin\jusched.exe
    4852 C:\Program Files\Lenovo\Client Security Solution\cssauth.exe
    4872 C:\Program Files\Windows Sidebar\sidebar.exe
    4924 C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    4976 C:\Windows\System32\igfxsrvc.exe
    5052 C:\Program Files (x86)\Digital Line Detect\DLG.exe
    5060 C:\Program Files (x86)\McAfee Security Scan\2.0.181\SSScheduler.exe
    5068 C:\Program Files (x86)\RotateImage\RCIMGDIR.exe
    5088 C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe
    3744 C:\Program Files (x86)\Lenovo\NPDIRECT\tpfnf7sp.exe
    2252 C:\Program Files (x86)\ThinkPad\Utilities\EZEJMNAP.EXE
    4120 C:\Program Files (x86)\Common Files\Lenovo\Scheduler\scheduler_proxy.exe
    2860 C:\Program Files (x86)\ThinkVantage\PrdCtr\LPMGR.EXE
    2844 C:\Program Files (x86)\ThinkVantage\PrdCtr\LPMLCHK.EXE
    2840 C:\Program Files (x86)\ThinkVantage\AMSG\Amsg.exe
    2976 C:\Program Files (x86)\Lenovo2\Drag-to-Disc\DrgToDsc.exe
    160 C:\Windows\SysWOW64\rundll32.exe
    3720 C:\Program Files\Lenovo\ZOOM\TpScrex.exe
    4112 C:\Program Files (x86)\ThinkPad\ConnectUtilities\ACTray.exe
    4216 C:\Program Files (x86)\ThinkPad\ConnectUtilities\ACWLIcon.exe
    896 C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\acrotray.exe
    2724 C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
    960 C:\Program Files (x86)\Seagate\SeagateManager\FreeAgent Status\stxmenumgr.exe
    4504 C:\Program Files (x86)\iTunes\iTunesHelper.exe
    4460 C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
    4296 C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
    1844 C:\Program Files (x86)\Lenovo\Camera Center\bin\LenovoCameraCenter.exe
    4480 C:\Windows\System32\rundll32.exe
    5296 C:\Program Files\iPod\bin\iPodService.exe
    3800 C:\Windows\System32\svchost.exe
    3656 C:\PROGRA~2\ThinkPad\UTILIT~1\PWMUIAux.EXE
    5464 C:\Program Files (x86)\Yahoo!\Messenger\Ymsgr_tray.exe
    5976 C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
    3120 C:\Windows\System32\wuauclt.exe
    5828 C:\Program Files (x86)\Internet Explorer\iexplore.exe
    4184 C:\Program Files (x86)\Internet Explorer\iexplore.exe
    3172 C:\Windows\SysWOW64\Macromed\Flash\FlashUtil10p_Ac tiveX.exe
    5132 C:\Program Files (x86)\Internet Explorer\iexplore.exe
    4576 C:\Users\lqi\Desktop\anti_virus\20zu1ehy.exe
    5880 C:\Windows\System32\SearchProtocolHost.exe
    4564 C:\Windows\System32\SearchFilterHost.exe
    4632 C:\Program Files (x86)\Internet Explorer\iexplore.exe
    5960 C:\Windows\System32\SearchProtocolHost.exe
    2908 dllhost.exe
    5224 dllhost.exe
    4752 C:\Users\lqi\Desktop\anti_virus\MBRCheck.exe
    2364 C:\Windows\SysWOW64\conime.exe

    \\.\C: --> \\.\PhysicalDrive0 at offset 0x00000000`5dd00000 (NTFS)
    \\.\Q: --> \\.\PhysicalDrive0 at offset 0x00000037`c7a00000 (NTFS)
    \\.\S: --> \\.\PhysicalDrive0 at offset 0x00000000`00100000 (NTFS)

    PhysicalDrive0 Model Number: WDCWD2500BEVS-08VAT2, Rev: 14.01A14

    Size Device Name MBR Status
    --------------------------------------------
    232 GB \\.\PhysicalDrive0 Windows 2008 MBR code detected
    SHA1: 8DF43F2BDE2D9451948FA14B5279969C777A7979


    Done!

    From DDS:

    .
    DDS (Ver_2011-06-03.01) - NTFSAMD64
    Internet Explorer: 8.0.6001.19048 BrowserJavaVersion: 1.6.0_21
    Run by lqi at 13:45:44 on 2011-06-04
    Microsoft® Windows Vista™ Business 6.0.6002.2.1252.1.1033.18.2967.920 [GMT -4:00]
    .
    AV: AntiVir Desktop *Enabled/Updated* {090F9C29-64CE-6C6F-379C-5901B49A85B7}
    SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    SP: AntiVir Desktop *Enabled/Updated* {B26E7DCD-42F4-63E1-0D2C-6273CF1DCF0A}
    .
    ============== Running Processes ===============
    .
    C:\Windows\system32\wininit.exe
    C:\Windows\system32\lsm.exe
    C:\Windows\system32\svchost.exe -k DcomLaunch
    C:\Windows\system32\ibmpmsvc.exe
    C:\Windows\system32\svchost.exe -k rpcss
    C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
    C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
    C:\Windows\system32\svchost.exe -k netsvcs
    C:\Windows\system32\svchost.exe -k GPSvcGroup
    C:\Windows\system32\SLsvc.exe
    C:\Windows\system32\svchost.exe -k LocalService
    C:\Windows\system32\svchost.exe -k NetworkService
    C:\Windows\system32\WLANExt.exe
    C:\Windows\System32\spoolsv.exe
    C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
    C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
    C:\Program Files\LENOVO\HOTKEY\TPHKSVC.exe
    C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
    C:\Program Files (x86)\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
    C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
    C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
    C:\Program Files (x86)\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
    C:\Program Files (x86)\Bonjour\mDNSResponder.exe
    C:\Program Files\Intel\WiFi\bin\EvtEng.exe
    C:\Program Files (x86)\Seagate\SeagateManager\Sync\FreeAgentService .exe
    C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe
    C:\Program Files (x86)\Intel\AMT\LMS.exe
    C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
    C:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.EXE
    C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
    c:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe
    c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
    C:\Windows\system32\svchost.exe -k imgsvc
    c:\Program Files (x86)\Common Files\Lenovo\tvt_reg_monitor_svc.exe
    C:\Windows\System32\TPHDEXLG64.exe
    C:\Program Files (x86)\Lenovo\Client Security Solution\tvttcsd.exe
    C:\Program Files (x86)\Lenovo\Rescue and Recovery\rrpservice.exe
    C:\Program Files (x86)\Lenovo\Rescue and Recovery\rrservice.exe
    c:\Program Files (x86)\Common Files\Lenovo\Scheduler\tvtsched.exe
    C:\Program Files (x86)\Common Files\Intel\Privacy Icon\UNS\UNS.exe
    C:\Windows\System32\svchost.exe -k WerSvcGroup
    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
    C:\Windows\system32\SearchIndexer.exe
    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
    C:\Windows\system32\DRIVERS\xaudio64.exe
    C:\Windows\system32\wbem\wmiprvse.exe
    C:\Windows\system32\taskeng.exe
    C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe
    C:\Windows\system32\Dwm.exe
    C:\Windows\Explorer.EXE
    C:\Program Files (x86)\ThinkPad\ConnectUtilities\AcSvc.exe
    c:\Program Files (x86)\Lenovo\System Update\SUService.exe
    C:\Program Files (x86)\ThinkPad\ConnectUtilities\SvcGuiHlpr.exe
    c:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
    C:\Windows\system32\wbem\wmiprvse.exe
    C:\Program Files\Lenovo\TrackPoint\tp4serv.exe
    C:\Program Files (x86)\Common Files\Intel\Privacy Icon\PrivacyIconClient.exe
    C:\Windows\system32\taskeng.exe
    C:\Windows\System32\TpShocks.exe
    C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe
    C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe
    C:\Program Files\Lenovo\HOTKEY\tpfnf6r.exe
    C:\Windows\System32\igfxtray.exe
    C:\Windows\System32\hkcmd.exe
    C:\Windows\System32\igfxpers.exe
    C:\Program Files\Java\jre6\bin\jusched.exe
    C:\Program Files\Lenovo\Client Security Solution\cssauth.exe
    C:\Program Files\Windows Sidebar\sidebar.exe
    C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    C:\Windows\system32\igfxsrvc.exe
    C:\Program Files (x86)\Digital Line Detect\DLG.exe
    C:\Program Files (x86)\McAfee Security Scan\2.0.181\SSScheduler.exe
    C:\Program Files (x86)\RotateImage\RCIMGDIR.exe
    C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe
    C:\Program Files (x86)\Lenovo\NPDIRECT\tpfnf7sp.exe
    C:\Program Files (x86)\ThinkPad\Utilities\EZEJMNAP.EXE
    C:\Program Files (x86)\Common Files\Lenovo\Scheduler\scheduler_proxy.exe
    C:\Program Files (x86)\ThinkVantage\PrdCtr\LPMGR.EXE
    C:\Program Files (x86)\ThinkVantage\PrdCtr\LPMLCHK.EXE
    C:\Program Files (x86)\ThinkVantage\AMSG\Amsg.exe
    C:\Program Files (x86)\Lenovo2\Drag-to-Disc\DrgToDsc.exe
    C:\Windows\SysWOW64\rundll32.exe
    C:\Program Files\Lenovo\Zoom\TpScrex.exe
    C:\Program Files (x86)\ThinkPad\ConnectUtilities\ACTray.exe
    C:\Program Files (x86)\ThinkPad\ConnectUtilities\ACWLIcon.exe
    C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\acrotray.exe
    C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
    C:\Program Files (x86)\Seagate\SeagateManager\FreeAgent Status\stxmenumgr.exe
    C:\Program Files (x86)\iTunes\iTunesHelper.exe
    C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
    C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
    C:\Program Files (x86)\Lenovo\Camera Center\bin\LenovoCameraCenter.exe
    C:\Windows\system32\rundll32.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
    C:\PROGRA~2\ThinkPad\UTILIT~1\PWMUIAux.exe
    C:\Program Files (x86)\Yahoo!\Messenger\ymsgr_tray.exe
    C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
    C:\Windows\system32\wuauclt.exe
    C:\Program Files (x86)\Internet Explorer\iexplore.exe
    C:\Program Files (x86)\Internet Explorer\iexplore.exe
    C:\Windows\SysWOW64\Macromed\Flash\FlashUtil10p_Ac tiveX.exe
    C:\Program Files (x86)\Internet Explorer\iexplore.exe
    C:\Users\lqi\Desktop\anti_virus\20zu1ehy.exe
    C:\Windows\system32\SearchProtocolHost.exe
    C:\Windows\SysWOW64\conime.exe
    C:\Windows\system32\DllHost.exe
    C:\Windows\system32\DllHost.exe
    C:\Windows\SysWOW64\cmd.exe
    C:\Windows\SysWOW64\cscript.exe
    .
    ============== Pseudo HJT Report ===============
    .
    uSearch Page = hxxp://www.google.com
    uStart Page = hxxp://www.yahoo.com
    uDefault_Page_URL = hxxp://lenovo.live.com
    uSearch Bar = hxxp://www.google.com/ie
    uDefault_Search_URL = hxxp://www.google.com/ie
    mDefault_Page_URL = hxxp://lenovo.live.com
    uInternet Settings,ProxyOverride = *.local
    uSearchAssistant = hxxp://www.google.com/ie
    uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
    BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
    BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    BHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
    BHO: IePasswordManagerHelper Class: {bf468356-bb7e-42d7-9f15-4f3b9bcfced2} - C:\Program Files (x86)\Lenovo\Client Security Solution\tvtpwm_ie_com.dll
    BHO: WOT Helper: {c920e44a-7f78-4e64-bdd7-a57026e7feb7} - C:\Program Files (x86)\WOT\WOT.dll
    BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
    BHO: SmartSelect Class: {f4971ee7-daa0-4053-9964-665d8ee6a077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
    TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
    TB: WOT: {71576546-354d-41c9-aae8-31f2ec22bf0d} - C:\Program Files (x86)\WOT\WOT.dll
    uRun: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
    uRun: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background
    uRun: [Messenger (Yahoo!)] "C:\PROGRA~2\Yahoo!\Messenger\YahooMessenger.e xe" -quiet
    uRun: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    mRun: [TPFNF7] "C:\Program Files (x86)\Lenovo\NPDIRECT\TPFNF7SP.exe" /r
    mRun: [EZEJMNAP] C:\PROGRA~2\ThinkPad\UTILIT~1\EzEjMnAp.Exe
    mRun: [TVT Scheduler Proxy] C:\Program Files (x86)\Common Files\Lenovo\Scheduler\scheduler_proxy.exe
    mRun: [LPManager] C:\PROGRA~2\THINKV~1\PrdCtr\LPMGR.exe
    mRun: [LPMailChecker] C:\PROGRA~2\THINKV~1\PrdCtr\LPMLCHK.exe
    mRun: [AMSG] "C:\Program Files (x86)\ThinkVantage\AMSG\Amsg.exe" /startup
    mRun: [CameraApplicationLauncher] C:\Program Files (x86)\Lenovo\Camera Center\bin\CameraApplicationLaunchpadLauncher.exe
    mRun: [RoxioDragToDisc] "C:\Program Files (x86)\Lenovo2\Drag-to-Disc\DrgToDsc.exe"
    mRun: [PWMTRV] rundll32 C:\PROGRA~2\ThinkPad\UTILIT~1\PWMTR64V.DLL,PwrMgrB kGndMonitor
    mRun: [BLOG] rundll32 C:\PROGRA~2\ThinkPad\UTILIT~1\BTVLogEx.DLL,StartBa ttLog
    mRun: [CreateLMBCShortCut] "C:\Program Files (x86)\Lenovo\Mobile Broadband Connect\UserShortcutCreator.exe"
    mRun: [ACTray] C:\Program Files (x86)\ThinkPad\ConnectUtilities\ACTray.exe
    mRun: [ACWlIcon] C:\Program Files (x86)\ThinkPad\ConnectUtilities\ACWlIcon.exe
    mRun: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
    mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
    mRun: [Adobe Acrobat Speed Launcher] "C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe"
    mRun: [Acrobat Assistant 8.0] "C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe"
    mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
    mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
    mRun: [CarboniteSetupLite] "C:\Program Files (x86)\Carbonite\CarbonitePreinstaller.exe" /preinstalled /showonfirst /reshowat=900
    mRun: [MaxMenuMgr] "C:\Program Files (x86)\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe"
    mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
    mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
    mRun: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
    mRun: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
    mRun: [Malwarebytes' Anti-Malware (reboot)] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
    StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Sta rtup\DIGITA~1.LNK - C:\Program Files (x86)\Digital Line Detect\DLG.exe
    StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Sta rtup\MCAFEE~1.LNK - C:\Program Files (x86)\McAfee Security Scan\2.0.181\SSScheduler.exe
    StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Sta rtup\RCIMGD~1.LNK - C:\Program Files (x86)\RotateImage\RCIMGDIR.exe
    mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
    mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
    IE: Add to Google Photos Screensa&ver - C:\Windows\system32\GPhotos.scr/200
    IE: Append Link Target to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
    IE: Append to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
    IE: Convert Link Target to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
    IE: Convert to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
    IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
    IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
    IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
    IE: {F4F55DC8-0B69-4DFE-BA94-CB677B88B2A3} - {F4F55DC8-0B69-4DFE-BA94-CB677B88B2A3} - C:\Program Files (x86)\Lenovo\Client Security Solution\tvtpwm_ie_com.dll
    DPF: {8A0019EB-51FA-4AE5-A40B-C0496BBFC739} - hxxp://picture.vzw.com/activex/VerizonWirelessUploadControl.cab
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
    DPF: {AC414988-E5BB-4C2C-873B-EA53D2F3D23A} - hxxp://t.live.cctv.com/ieocx/CCTVUpdateInstall.dll
    DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
    TCP: DhcpNameServer = 68.87.68.166 68.87.74.166
    TCP: Interfaces\{395AFEDA-7FBE-45D7-959C-3C3D7D883C12} : NameServer = 0.0.0.0
    TCP: Interfaces\{3DE8E9A3-8AFA-4182-A6DF-C0CB2B68C0A9} : DhcpNameServer = 68.87.68.166 68.87.74.166
    Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
    Handler: wot - {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files (x86)\WOT\WOT.dll
    AppInit_DLLs: acaptuser32.dll
    SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
    LSA: Notification Packages = scecli ACGina
    BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    BHO-X64: AcroIEHelperStub - No File
    BHO-X64: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
    BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    BHO-X64: Adobe PDF Conversion Toolbar Helper: {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
    BHO-X64: IePasswordManagerHelper Class: {BF468356-BB7E-42D7-9F15-4F3B9BCFCED2} - C:\Program Files (x86)\Lenovo\Client Security Solution\tvtpwm_ie_com.dll
    BHO-X64: Password Manager Browser Helper Object - No File
    BHO-X64: WOT Helper: {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - C:\Program Files (x86)\WOT\WOT.dll
    BHO-X64: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
    BHO-X64: SmartSelect Class: {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
    BHO-X64: SmartSelect - No File
    TB-X64: Adobe PDF: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
    TB-X64: WOT: {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files (x86)\WOT\WOT.dll
    mRun-x64: [TPFNF7] "C:\Program Files (x86)\Lenovo\NPDIRECT\TPFNF7SP.exe" /r
    mRun-x64: [EZEJMNAP] C:\PROGRA~2\ThinkPad\UTILIT~1\EzEjMnAp.Exe
    mRun-x64: [TVT Scheduler Proxy] C:\Program Files (x86)\Common Files\Lenovo\Scheduler\scheduler_proxy.exe
    mRun-x64: [LPManager] C:\PROGRA~2\THINKV~1\PrdCtr\LPMGR.exe
    mRun-x64: [LPMailChecker] C:\PROGRA~2\THINKV~1\PrdCtr\LPMLCHK.exe
    mRun-x64: [AMSG] "C:\Program Files (x86)\ThinkVantage\AMSG\Amsg.exe" /startup
    mRun-x64: [CameraApplicationLauncher] C:\Program Files (x86)\Lenovo\Camera Center\bin\CameraApplicationLaunchpadLauncher.exe
    mRun-x64: [RoxioDragToDisc] "C:\Program Files (x86)\Lenovo2\Drag-to-Disc\DrgToDsc.exe"
    mRun-x64: [PWMTRV] rundll32 C:\PROGRA~2\ThinkPad\UTILIT~1\PWMTR64V.DLL,PwrMgrB kGndMonitor
    mRun-x64: [BLOG] rundll32 C:\PROGRA~2\ThinkPad\UTILIT~1\BTVLogEx.DLL,StartBa ttLog
    mRun-x64: [CreateLMBCShortCut] "C:\Program Files (x86)\Lenovo\Mobile Broadband Connect\UserShortcutCreator.exe"
    mRun-x64: [ACTray] C:\Program Files (x86)\ThinkPad\ConnectUtilities\ACTray.exe
    mRun-x64: [ACWlIcon] C:\Program Files (x86)\ThinkPad\ConnectUtilities\ACWlIcon.exe
    mRun-x64: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
    mRun-x64: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
    mRun-x64: [Adobe Acrobat Speed Launcher] "C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe"
    mRun-x64: [Acrobat Assistant 8.0] "C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe"
    mRun-x64: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
    mRun-x64: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
    mRun-x64: [CarboniteSetupLite] "C:\Program Files (x86)\Carbonite\CarbonitePreinstaller.exe" /preinstalled /showonfirst /reshowat=900
    mRun-x64: [MaxMenuMgr] "C:\Program Files (x86)\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe"
    mRun-x64: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
    mRun-x64: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
    mRun-x64: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
    mRun-x64: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
    mRun-x64: [Malwarebytes' Anti-Malware (reboot)] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
    AppInit_DLLs-X64: acaptuser32.dll
    SEH-X64: Groove GFS Stub Execution Hook: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
    .
    ================= FIREFOX ===================
    .
    FF - ProfilePath - C:\Users\lqi\AppData\Roaming\Mozilla\Firefox\Profi les\d7tyfmwv.default\
    FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com
    FF - plugin: C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll
    FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
    FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
    FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - C:\Program Files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
    FF - Ext: Java Console: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
    FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
    .
    ---- FIREFOX POLICIES ----
    FF - user.js: yahoo.ytff.general.dontshowhpoffer - true
    ============= SERVICES / DRIVERS ===============
    .
    R0 DRVECDB;DRVECDB;C:\Windows\system32\Drivers\DRVECD B.SYS --> C:\Windows\system32\Drivers\DRVECDB.SYS [?]
    R0 PxHlpa64;PxHlpa64;C:\Windows\system32\Drivers\PxHl pa64.sys --> C:\Windows\system32\Drivers\PxHlpa64.sys [?]
    R0 TPDIGIMN;TPDIGIMN;C:\Windows\system32\DRIVERS\ApsH M64.sys --> C:\Windows\system32\DRIVERS\ApsHM64.sys [?]
    R1 DLACDBHE;DLACDBHE;C:\Windows\system32\Drivers\DLAC DBHE.SYS --> C:\Windows\system32\Drivers\DLACDBHE.SYS [?]
    R1 DLARTL_E;DLARTL_E;C:\Windows\system32\Drivers\DLAR TL_E.SYS --> C:\Windows\system32\Drivers\DLARTL_E.SYS [?]
    R1 lenovo.smi;Lenovo System Interface Driver;C:\Windows\system32\DRIVERS\smiifx64.sys --> C:\Windows\system32\DRIVERS\smiifx64.sys [?]
    R1 SASDIFSV;SASDIFSV;C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys [2010-2-17 14920]
    R1 SASKUTIL;SASKUTIL;C:\Program Files\SUPERAntiSpyware\saskutil64.sys [2010-2-17 12360]
    R2 !SASCORE;SAS Core Service;C:\Program Files\SUPERAntiSpyware\SASCore64.exe [2010-6-29 128752]
    R2 AntiVirSchedulerService;Avira AntiVir Scheduler;C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [2011-6-3 136360]
    R2 AntiVirService;Avira AntiVir Guard;C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [2011-6-3 269480]
    R2 avgntflt;avgntflt;C:\Windows\system32\DRIVERS\avgn tflt.sys --> C:\Windows\system32\DRIVERS\avgntflt.sys [?]
    R2 DLABMFSE;DLABMFSE;C:\Windows\system32\DLA\DLABMFSE .SYS --> C:\Windows\system32\DLA\DLABMFSE.SYS [?]
    R2 DLABOIOE;DLABOIOE;C:\Windows\system32\DLA\DLABOIOE .SYS --> C:\Windows\system32\DLA\DLABOIOE.SYS [?]
    R2 DLADResE;DLADResE;C:\Windows\system32\DLA\DLADResE .SYS --> C:\Windows\system32\DLA\DLADResE.SYS [?]
    R2 DLAIFS_E;DLAIFS_E;C:\Windows\system32\DLA\DLAIFS_E .SYS --> C:\Windows\system32\DLA\DLAIFS_E.SYS [?]
    R2 DLAOPIOE;DLAOPIOE;C:\Windows\system32\DLA\DLAOPIOE .SYS --> C:\Windows\system32\DLA\DLAOPIOE.SYS [?]
    R2 DLAPoolE;DLAPoolE;C:\Windows\system32\DLA\DLAPoolE .SYS --> C:\Windows\system32\DLA\DLAPoolE.SYS [?]
    R2 DLAUDF_E;DLAUDF_E;C:\Windows\system32\DLA\DLAUDF_E .SYS --> C:\Windows\system32\DLA\DLAUDF_E.SYS [?]
    R2 DLAUDFAE;DLAUDFAE;C:\Windows\system32\DLA\DLAUDFAE .SYS --> C:\Windows\system32\DLA\DLAUDFAE.SYS [?]
    R2 DRVEDDM;DRVEDDM;C:\Windows\system32\Drivers\DRVEDD M.SYS --> C:\Windows\system32\Drivers\DRVEDDM.SYS [?]
    R2 FontCache;Windows Font Cache Service;C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-20 21504]
    R2 FreeAgentGoNext Service;Seagate Service;C:\Program Files (x86)\Seagate\SeagateManager\Sync\FreeAgentService .exe [2009-9-26 189736]
    R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2010-8-5 366640]
    R2 Power Manager DBC Service;Power Manager DBC Service;C:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.exe [2009-8-5 66848]
    R2 TPHKSVC;On Screen Display;C:\Program Files\Lenovo\HOTKEY\TPHKSVC.exe [2009-6-12 62320]
    R2 TVT Backup Protection Service;TVT Backup Protection Service;C:\Program Files (x86)\Lenovo\Rescue and Recovery\rrpservice.exe [2008-5-24 520192]
    R2 UNS;Intel(R) Active Management Technology User Notification Service;C:\Program Files (x86)\Common Files\Intel\Privacy Icon\UNS\UNS.exe [2009-8-5 2058776]
    R3 5U875UVC;Integrated Camera;C:\Windows\system32\DRIVERS\5U875.sys --> C:\Windows\system32\DRIVERS\5U875.sys [?]
    R3 CAXHWAZL;CAXHWAZL;C:\Windows\system32\DRIVERS\CAXH WAZL.sys --> C:\Windows\system32\DRIVERS\CAXHWAZL.sys [?]
    R3 e1yexpress;Intel(R) Gigabit Network Connections Driver;C:\Windows\system32\DRIVERS\e1y60x64.sys --> C:\Windows\system32\DRIVERS\e1y60x64.sys [?]
    R3 HECIx64;Intel(R) Management Engine Interface;C:\Windows\system32\DRIVERS\HECIx64.sys --> C:\Windows\system32\DRIVERS\HECIx64.sys [?]
    R3 MBAMProtector;MBAMProtector;\??\C:\Windows\system3 2\drivers\mbam.sys --> C:\Windows\system32\drivers\mbam.sys [?]
    R3 MUXMP;My WiFi PAN MUX-IM Virtual Miniport Driver;C:\Windows\system32\DRIVERS\mux.sys --> C:\Windows\system32\DRIVERS\mux.sys [?]
    R3 NETw5v64;Intel(R) Wireless WiFi Link Adapter Driver for Windows Vista 64 Bit ;C:\Windows\system32\DRIVERS\NETw5v64.sys --> C:\Windows\system32\DRIVERS\NETw5v64.sys [?]
    R3 Tp4Track;PS/2 TrackPoint Driver;C:\Windows\system32\DRIVERS\tp4track.sys --> C:\Windows\system32\DRIVERS\tp4track.sys [?]
    R3 TVTI2C;Lenovo SM bus driver;C:\Windows\system32\DRIVERS\Tvti2c.sys --> C:\Windows\system32\DRIVERS\Tvti2c.sys [?]
    S1 tvtumon;tvtumon;C:\Windows\system32\DRIVERS\tvtumo n.sys --> C:\Windows\system32\DRIVERS\tvtumon.sys [?]
    S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\ v4.0.30319\mscorsvw.exe [2010-3-18 130384]
    S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework6 4\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
    S2 LENOVO.MICMUTE;Lenovo Microphone Mute;C:\Program Files\Lenovo\HOTKEY\micmute.exe [2009-6-12 45424]
    S2 TVT_UpdateMonitor;TVT Windows Update Monitor;C:\Program Files (x86)\Lenovo\Rescue and Recovery\UpdateMonitor.exe [2008-5-24 360448]
    S2 WebUpdate4;Web Update Wizard Service V4;C:\Windows\SysWOW64\WebUpdateSvc4.exe --> C:\Windows\SysWOW64\WebUpdateSvc4.exe [?]
    S3 ICDUSB3;ICDUSB3;C:\Windows\system32\Drivers\ICDUSB 3.sys --> C:\Windows\system32\Drivers\ICDUSB3.sys [?]
    S3 McComponentHostService;McAfee Security Scan Component Host Service;C:\Program Files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe [2010-1-15 227232]
    S3 MosIrUsb;MosIrUsb.sys;C:\Windows\system32\DRIVERS\ MosIrUsb.sys --> C:\Windows\system32\DRIVERS\MosIrUsb.sys [?]
    S3 motccgp;Motorola USB Composite Device Driver;C:\Windows\system32\DRIVERS\motccgp.sys --> C:\Windows\system32\DRIVERS\motccgp.sys [?]
    S3 motccgpfl;MotCcgpFlService;C:\Windows\system32\DRI VERS\motccgpfl.sys --> C:\Windows\system32\DRIVERS\motccgpfl.sys [?]
    S3 MUXP;My WiFi PAN Mux-IM Protocol Driver;C:\Windows\system32\DRIVERS\mux.sys --> C:\Windows\system32\DRIVERS\mux.sys [?]
    S3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [2009-2-11 306688]
    S3 PerfHost;Performance Counter DLL Host;C:\Windows\SysWOW64\perfhost.exe [2008-1-20 19968]
    S3 PSI;PSI;C:\Windows\system32\DRIVERS\psi_mf.sys --> C:\Windows\system32\DRIVERS\psi_mf.sys [?]
    S3 RoxMediaDB10;RoxMediaDB10;C:\Program Files (x86)\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe [2008-4-25 1120752]
    S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\system32\Drivers\usbaapl64.sys --> C:\Windows\system32\Drivers\usbaapl64.sys [?]
    S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;C:\Windows\Microsoft.NET\Framework64\v4.0. 30319\WPF\WPFFontCache_v0400.exe [2010-3-18 1020768]
    S4 clr_optimization_v2.0.50727_64;Microsoft .NET Framework NGEN v2.0.50727_X64;C:\Windows\Microsoft.NET\Framework6 4\v2.0.50727\mscorsvw.exe [2010-8-15 89920]
    .
    =============== File Associations ===============
    .
    JSEFile=C:\Windows\SysWOW64\WScript.exe "%1" %*
    .
    =============== Created Last 30 ================
    .
    2011-06-04 14:07:39 -------- d-----w- C:\Users\lqi\AppData\Local\{47C613AD-D7AD-41CA-B28D-7BAE879DC7E7}
    2011-06-03 16:22:20 83120 ----a-w- C:\Windows\System32\drivers\avgntflt.sys
    2011-06-03 16:22:19 -------- d-----w- C:\ProgramData\Avira
    2011-06-03 16:22:19 -------- d-----w- C:\Program Files (x86)\Avira
    2011-06-03 16:07:19 8718160 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{1B5AFB27-65F2-4991-9128-B4545837DD54}\mpengine.dll
    2011-06-03 16:01:08 -------- d-----w- C:\Users\lqi\AppData\Local\{86012517-AA7B-47DA-BF15-62511678C91F}
    2011-06-02 15:48:34 -------- d-----w- C:\Users\lqi\AppData\Roaming\SUPERAntiSpyware.com
    2011-06-02 15:48:34 -------- d-----w- C:\ProgramData\SUPERAntiSpyware.com
    2011-06-02 15:48:29 -------- d-----w- C:\ProgramData\!SASCORE
    2011-06-02 15:48:25 -------- d-----w- C:\Program Files\SUPERAntiSpyware
    2011-06-02 14:51:32 -------- d-sh--w- C:\ProgramData\PSRAYUJG
    2011-06-02 14:51:12 -------- d-sh--w- C:\ProgramData\9c9680
    2011-06-02 14:08:51 -------- d-----w- C:\Users\lqi\AppData\Local\{F05907DF-7EDD-4423-856A-D0FF4380B98B}
    2011-06-01 22:33:41 -------- d-----w- C:\Users\lqi\AppData\Local\{2599A179-C367-462C-9D09-C9BE144C6151}
    2011-05-31 21:54:50 -------- d-----w- C:\Users\lqi\AppData\Local\{44B609B0-D76B-496D-AC23-F2683C36463E}
    2011-05-31 14:27:23 -------- d-----w- C:\Users\lqi\AppData\Local\{30974079-FCC4-4FEB-A28C-6686553205B4}
    2011-05-29 17:32:22 -------- d-----w- C:\Users\lqi\AppData\Local\{22AB9743-4382-4C46-9A18-DB1103E2C332}
    2011-05-28 17:43:22 -------- d-----w- C:\Users\lqi\AppData\Local\{3D83FBD6-96BA-49FE-90F2-57E21AED61F2}
    2011-05-27 21:03:17 -------- d-----w- C:\Users\lqi\AppData\Local\{6027B214-2254-41E9-BA0C-27EDBB51444D}
    2011-05-26 18:59:30 -------- d-----w- C:\Users\lqi\AppData\Local\{7FACE21B-7B07-4C40-9A7A-769005C6C280}
    2011-05-26 13:47:47 -------- d-----w- C:\Users\lqi\AppData\Local\{B5227B09-562F-4738-AB91-BCCFDAF356E0}
    2011-05-23 19:23:36 -------- d-----w- C:\Users\lqi\AppData\Local\{1C35662B-EB08-4FC4-B5C9-ACC7E4CD37DB}
    2011-05-21 18:23:14 -------- d-----w- C:\Users\lqi\AppData\Local\{70D9CF81-81CF-4274-9FCE-9B1C41CED19F}
    2011-05-20 15:44:05 -------- d-----w- C:\Users\lqi\AppData\Local\{71BFEB9D-7CE7-4F25-80D1-1E9647F96F97}
    2011-05-19 04:15:46 -------- d-----w- C:\Users\lqi\AppData\Local\{D5BF2E1A-A18A-4EC2-808C-1AE2298F7700}
    2011-05-18 15:09:01 -------- d-----w- C:\Users\lqi\AppData\Local\{F9116545-AC47-47C7-8346-7E6E6772E2F6}
    2011-05-17 22:01:59 -------- d-----w- C:\Users\lqi\AppData\Local\{846E8560-EBDA-41B6-AEDE-604BD85E5DBC}
    2011-05-17 03:12:09 -------- d-----w- C:\Users\lqi\AppData\Local\{DD24F0E7-5723-4A8E-9052-A220A2931623}
    2011-05-16 15:11:31 -------- d-----w- C:\Users\lqi\AppData\Local\{9FB0004E-AFAE-43E5-8351-63728D73657D}
    2011-05-15 16:41:32 -------- d-----w- C:\Users\lqi\AppData\Local\{07055C99-2753-4360-95E7-B07ED4C70AC7}
    2011-05-15 03:44:43 -------- d-----w- C:\Users\lqi\AppData\Local\{2D540C3C-8AEF-4377-AFB5-B39572D605C2}
    2011-05-12 21:47:48 -------- d-----w- C:\Users\lqi\AppData\Local\{73D5611E-8E72-4620-9274-F4D5B6F198CE}
    2011-05-12 00:31:17 2409784 ----a-w- C:\Program Files (x86)\Windows Mail\OESpamFilter.dat
    2011-05-12 00:31:16 2409784 ----a-w- C:\Program Files\Windows Mail\OESpamFilter.dat
    2011-05-12 00:17:01 -------- d-----w- C:\Users\lqi\AppData\Local\{DFD6E4D3-1B0D-4377-9CBB-E7F2087EDD6B}
    2011-05-10 02:04:03 -------- d-----w- C:\Users\lqi\AppData\Local\{7E60F79F-2C5A-4799-AECA-3ED34246ED6A}
    2011-05-09 23:17:14 -------- d-----w- C:\Users\lqi\AppData\Local\{84E3A561-CA30-4323-B7AF-D0CAF3217DEF}
    2011-05-07 14:54:46 -------- d-----w- C:\Users\lqi\AppData\Local\{DE6A09E6-6A1F-46F7-BC63-EAB0EFE6FA58}
    .
    ==================== Find3M ====================
    .
    2011-05-29 13:11:30 39984 ----a-w- C:\Windows\SysWow64\drivers\mbamswissarmy.sys
    2011-05-29 13:11:20 25912 ----a-w- C:\Windows\System32\drivers\mbam.sys
    2011-03-12 22:52:03 1653760 ----a-w- C:\Windows\System32\XpsPrint.dll
    2011-03-12 21:55:52 876032 ----a-w- C:\Windows\SysWow64\XpsPrint.dll
    2011-03-10 17:18:03 1360384 ----a-w- C:\Windows\System32\mfc42u.dll
    2011-03-10 17:18:02 1398784 ----a-w- C:\Windows\System32\mfc42.dll
    2011-03-10 17:03:51 1162240 ----a-w- C:\Windows\SysWow64\mfc42u.dll
    2011-03-10 17:03:51 1136640 ----a-w- C:\Windows\SysWow64\mfc42.dll
    .
    ============= FINISH: 13:46:25.05 ===============


    .
    UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
    IF REQUESTED, ZIP IT UP & ATTACH IT
    .
    DDS (Ver_2011-06-03.01)
    .
    Microsoft® Windows Vista™ Business
    Boot Device: \Device\HarddiskVolume1
    Install Date: 8/5/2009 12:15:08 PM
    System Uptime: 6/4/2011 12:15:53 PM (1 hours ago)
    .
    Motherboard: LENOVO | | 7465CTO
    Processor: Intel(R) Core(TM)2 Duo CPU L9400 @ 1.86GHz | None | 1866/266mhz
    .
    ==== Disk Partitions =========================
    .
    C: is FIXED (NTFS) - 222 GiB total, 37.887 GiB free.
    D: is CDROM ()
    Q: is FIXED (NTFS) - 10 GiB total, 2.531 GiB free.
    S: is FIXED (NTFS) - 1 GiB total, 0.676 GiB free.
    .
    ==== Disabled Device Manager Items =============
    .
    ==== System Restore Points ===================
    .
    RP473: 5/19/2011 1:09:27 PM - Scheduled Checkpoint
    RP474: 5/20/2011 11:51:31 AM - Windows Update
    RP475: 5/25/2011 4:14:03 PM - Windows Update
    RP476: 5/26/2011 10:41:33 AM - Scheduled Checkpoint
    RP477: 5/27/2011 5:10:12 PM - Windows Update
    RP478: 5/28/2011 5:31:59 PM - Scheduled Checkpoint
    RP479: 5/31/2011 10:34:35 AM - Windows Update
    RP480: 6/3/2011 12:06:29 PM - Windows Update
    RP481: 6/3/2011 12:15:14 PM - avast! Free Antivirus Setup
    RP482: 6/4/2011 1:36:22 PM - Scheduled Checkpoint
    .
    ==== Installed Programs ======================
    .
    .
    Update for Microsoft Office 2007 (KB2508958)
    2007 Microsoft Office system
    Access Help
    Acrobat.com
    Adobe Acrobat 9 Pro Extended - English, Français, Deutsch
    Adobe Acrobat 9.4.4 - CPSID_83708
    Adobe AIR
    Adobe Flash Player 10 ActiveX
    Adobe Flash Player 10 Plugin
    Adobe Reader 9.3
    Apple Application Support
    Apple Software Update
    AT&T Service Activation
    Avira AntiVir Personal - Free Antivirus
    Business Contact Manager for Outlook 2007 SP2
    CAJViewer
    Camera Center
    Canon G.726 WMP-Decoder
    Canon MovieEdit Task for ZoomBrowser EX
    Canon RAW Image Task for ZoomBrowser EX
    Canon Utilities CameraWindow
    Canon Utilities CameraWindow DC
    Canon Utilities CameraWindow DC_DV 6 for ZoomBrowser EX
    Canon Utilities MyCamera
    Canon Utilities MyCamera DC
    Canon Utilities PhotoStitch
    Canon Utilities RemoteCapture Task for ZoomBrowser EX
    Canon Utilities ZoomBrowser EX
    Canon ZoomBrowser EX Memory Card Utility
    Carbonite Online Backup Setup
    D3DX10
    DirectXInstallService
    EViews 6
    Help Center
    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
    Integrated Camera Driver Installer Package Ver.1.25.500.0
    Integrated Camera TWAIN
    InterVideo Register Manager
    InterVideo WinDVD
    Java Auto Updater
    Java(TM) 6 Update 21
    Lenovo Registration
    Lenovo Welcome
    Malwarebytes' Anti-Malware version 1.51.0.1200
    McAfee Security Scan Plus
    Message Center
    Microsoft Office 2003 Web Components
    Microsoft Office 2007 Primary Interop Assemblies
    Microsoft Office 2007 Service Pack 2 (SP2)
    Microsoft Office Access MUI (English) 2007
    Microsoft Office Access Setup Metadata MUI (English) 2007
    Microsoft Office Enterprise 2007
    Microsoft Office Excel MUI (English) 2007
    Microsoft Office Groove MUI (English) 2007
    Microsoft Office Groove Setup Metadata MUI (English) 2007
    Microsoft Office InfoPath MUI (English) 2007
    Microsoft Office OneNote MUI (English) 2007
    Microsoft Office Outlook MUI (English) 2007
    Microsoft Office PowerPoint MUI (English) 2007
    Microsoft Office Professional Hybrid 2007
    Microsoft Office Proof (English) 2007
    Microsoft Office Proof (French) 2007
    Microsoft Office Proof (Spanish) 2007
    Microsoft Office Proofing (English) 2007
    Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
    Microsoft Office Publisher MUI (English) 2007
    Microsoft Office Shared MUI (English) 2007
    Microsoft Office Shared Setup Metadata MUI (English) 2007
    Microsoft Office Small Business Connectivity Components
    Microsoft Office Suite Activation Assistant
    Microsoft Office Word MUI (English) 2007
    Microsoft Save as PDF or XPS Add-in for 2007 Microsoft Office programs
    Microsoft Silverlight
    Microsoft SQL Server 2005
    Microsoft SQL Server 2005 Express Edition (MSSMLBIZ)
    Microsoft SQL Server Setup Support Files (English)
    Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
    Microsoft Visual C++ 2005 Redistributable
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
    Mobile Broadband Connect
    Mozilla Firefox (3.6.8)
    MSVCRT
    MSXML 4.0 SP2 (KB954430)
    MSXML 4.0 SP2 (KB973688)
    muvee Reveal Seagate Edition
    Picasa 3
    PowerCmd 2.1
    Presentation Director
    Product Recovery Disc Burning Utility
    Productivity Center Supplement for ThinkPad
    QuickTime
    Registry patch to improve USB device detection on resume from sleep for Windows Vista
    Rescue and Recovery
    Roxio Activation Module
    Roxio Central Audio
    Roxio Central Copy
    Roxio Central Core
    Roxio Central Data
    Roxio Central Tools
    Roxio Creator Business Edition
    Roxio Express Labeler 3
    Safari
    Seagate Manager Installer
    Secunia PSI
    Security Update for 2007 Microsoft Office System (KB2288621)
    Security Update for 2007 Microsoft Office System (KB2288931)
    Security Update for 2007 Microsoft Office System (KB2345043)
    Security Update for 2007 Microsoft Office System (KB2466156)
    Security Update for 2007 Microsoft Office System (KB2509488)
    Security Update for 2007 Microsoft Office System (KB969559)
    Security Update for 2007 Microsoft Office System (KB976321)
    Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2160841)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)
    Security Update for Microsoft Office Access 2007 (KB979440)
    Security Update for Microsoft Office Excel 2007 (KB2464583)
    Security Update for Microsoft Office Groove 2007 (KB2494047)
    Security Update for Microsoft Office InfoPath 2007 (KB979441)
    Security Update for Microsoft Office PowerPoint 2007 (KB2535818)
    Security Update for Microsoft Office PowerPoint Viewer 2007 (KB2464623)
    Security Update for Microsoft Office Publisher 2007 (KB2284697)
    Security Update for Microsoft Office system 2007 (972581)
    Security Update for Microsoft Office system 2007 (KB974234)
    Security Update for Microsoft Office Visio Viewer 2007 (KB973709)
    Security Update for Microsoft Office Word 2007 (KB2344993)
    Segoe UI
    Sonic CinePlayer Decoder Pack
    Sonic Icons for Lenovo
    Spelling Dictionaries Support For Adobe Reader 9
    Stat/Transfer Nine
    Stata 10
    System Update
    ThinkPad EasyEject Utility
    ThinkPad Power Manager
    ThinkVantage Access Connections
    ThinkVantage Productivity Center
    ThinkVantage Technologies Welcome Message
    Update for 2007 Microsoft Office System (KB2284654)
    Update for 2007 Microsoft Office System (KB967642)
    Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
    Update for Microsoft Office 2007 Help for Common Features (KB963673)
    Update for Microsoft Office Access 2007 Help (KB963663)
    Update for Microsoft Office Excel 2007 Help (KB963678)
    Update for Microsoft Office Infopath 2007 Help (KB963662)
    Update for Microsoft Office OneNote 2007 (KB980729)
    Update for Microsoft Office OneNote 2007 Help (KB963670)
    Update for Microsoft Office Outlook 2007 (KB2509470)
    Update for Microsoft Office Outlook 2007 Help (KB963677)
    Update for Microsoft Office Powerpoint 2007 Help (KB963669)
    Update for Microsoft Office Publisher 2007 Help (KB963667)
    Update for Microsoft Office Script Editor Help (KB963671)
    Update for Microsoft Office Word 2007 Help (KB963665)
    Update for Outlook 2007 Junk Email Filter (KB2536413)
    Verizon Wireless Mobile Broadband Self Activation
    Wallpapers
    Web Update Wizard (Redistributable) 4.0
    Windows Live Communications Platform
    Windows Live Essentials
    Windows Live Installer
    Windows Live Messenger
    Windows Live Photo Common
    Windows Live PIMT Platform
    Windows Live SOXE
    Windows Live SOXE Definitions
    Windows Live UX Platform
    Windows Live UX Platform Language Pack
    WOT for Internet Explorer
    Yahoo! Messenger
    Yahoo! Software Update
    .
    ==== Event Viewer Messages From Past Week ========
    .
    6/4/2011 12:24:53 PM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the TrkWks service.
    6/4/2011 12:24:23 PM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the SysMain service.
    6/4/2011 12:16:58 PM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: tvtumon
    6/4/2011 12:16:58 PM, Error: Service Control Manager [7023] - The Lenovo Microphone Mute service terminated with the following error: Incorrect function.
    6/3/2011 12:22:43 PM, Error: Service Control Manager [7006] - The ScRegSetValueExW call failed for Start with the following error: Access is denied.
    6/3/2011 12:00:35 PM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the Irmon service.
    6/3/2011 12:00:05 PM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the hidserv service.
    6/3/2011 11:59:35 AM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the CscService service.
    6/3/2011 11:59:05 AM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the AudioEndpointBuilder service.
    6/3/2011 1134 AM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the WPDBusEnum service.
    6/1/2011 6:42:40 PM, Error: Service Control Manager [7010] - A timeout (30000 milliseconds) was reached while waiting for ReadFile.
    6/1/2011 6:32:06 PM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: cdrom tvtumon
    5/31/2011 5:55:06 PM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Windows Font Cache Service service to connect.
    5/31/2011 5:55:06 PM, Error: Service Control Manager [7000] - The Windows Font Cache Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
    5/31/2011 10:37:09 AM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the Netman service.
    5/31/2011 10:36:39 AM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the Wlansvc service.
    5/28/2011 4:34:19 PM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the Spooler service.
    5/28/2011 4:33:15 PM, Error: EventLog [6008] - The previous system shutdown at 4:31:51 PM on 5/28/2011 was unexpected.
    5/28/2011 4:26:22 PM, Error: Microsoft-Windows-TBS [516] - An error occurred while communicating with the TPM. The driver returned 0x8007001f.
    5/28/2011 4:26:22 PM, Error: Microsoft-Windows-TBS [16385] - An internal TBS error was detected. The error code was 0x8007001f. This is usually caused by unexpected TPM or driver behavior and may be transient.
    .
    ==== End Of File ===========================

  4. #4
    broni is offline Senior Member
    Please, do NOT create new topic just to post your logs.
    Continue everything right in this topic.
    This time, I merged both topics.


    ================================================== =========

    Please download ComboFix from Here or Here to your Desktop.

    **Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**
    1. Please, never rename Combofix unless instructed.
    2. Close any open browsers.
    3. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
      • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
      • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.

      NOTE1. If Combofix asks you to install Recovery Console, please allow it.
      NOTE 2. If Combofix asks you to update the program, always do so.
      • Close any open browsers.
      • WARNING: Combofix will disconnect your machine from the Internet as soon as it starts
      • Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
      • If there is no internet connection after running Combofix, then restart your computer to restore back your connection.
    4. Double click on combofix.exe & follow the prompts.
    5. When finished, it will produce a report for you.
    6. Please post the "C:\ComboFix.txt"

    **Note 1: Do not mouseclick combofix's window while it's running. That may cause it to stall
    **Note 2 for AVG users: ComboFix will not run until AVG is uninstalled as a protective measure against the anti-virus. This is because AVG "falsely" detects ComboFix (or its embedded files) as a threat and may remove them resulting in the tool not working correctly which in turn can cause "unpredictable results". Since AVG cannot be effectively disabled before running ComboFix, the author recommends you to uninstall AVG first.
    Use AppRemover to uninstall it: Uninstall & Remove McAfee, Symantec, Norton, AVG, Avast & More Antivirus and Security Applications and Programs
    We can reinstall it when we're done with CF.
    **Note 3: If you receive an error "Illegal operation attempted on a registery key that has been marked for deletion", restart computer to fix the issue.



    Make sure, you re-enable your security programs, when you're done with Combofix.

    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~~~

    NOTE.
    If, for some reason, Combofix refuses to run, try one of the following:

    1. Run Combofix from Safe Mode.

    2. Delete Combofix file, download fresh one, but rename combofix.exe to yourname.exe BEFORE saving it to your desktop.
    Do NOT run it yet.

    Please download and run the below tool named Rkill (courtesy of BleepingComputer.com) which may help allow other programs to run.

    There are 4 different versions. If one of them won't run then download and try to run the other one.

    Vista and Win7 users need to right click Rkill and choose Run as Administrator

    You only need to get one of these to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.

    Rkill.com
    Rkill.scr
    Rkill.exe

    • Double-click on the Rkill desktop icon to run the tool.
    • If using Vista or Windows 7 right-click on it and choose Run As Administrator.
    • A black DOS box will briefly flash and then disappear. This is normal and indicates the tool ran successfully.
    • If not, delete the file, then download and use the one provided in Link 2.
    • If it does not work, repeat the process and attempt to use one of the remaining links until the tool runs.
    • Do not reboot until instructed.
    • If the tool does not run from any of the links provided, please let me know.


    Once you've gotten one of them to run, immediately run your_name.exe by double clicking on it.

    If normal mode still doesn't work, run BOTH tools from safe mode.

    In case #2, please post BOTH logs, rKill and Combofix.

    DO NOT make any other changes to your computer (like installing programs, using other cleaning tools, etc.), until it's officially declared clean!!!

  5. #5
    qili26 is offline Junior Member
    I disabled firewall and other anti virus programs such as Avira. I ran combo fix. However, I didn't sit in front of the computer while combo fix was running. When returned, i saw the log in screen. So I am not sure whether combofix restartes my computer. I logged on and saw combofix's screen showing the message that says it's preparing log results. But for some reason, Avira popped a window that says that "guard: malware found. A virus or unwanted program 'TR/CryptXPACK.Gen' was found in file 'C:\ComboFix\handle.cfxxe.' access to this file was denied. Please select further section." then the choices are remove and details. Meanwhile the combofix screen displayed the log results after 5 minutes. I don't know why Avira became snaked again. Can you tell me whether i should choose remove or details? I tries to just close this window but it popped up again.

  6. #6
    qili26 is offline Junior Member
    Sorry I was using ipod to type in the last reply. So there were many typos. I meant why Avira started again (not "snaked")...

    Also, I forgot to paste the log results from combofix. Strangely I didn't find the log file at the location of C:\ComboFix.txt. But here is what showed up on the screen after ComboFix ran:

    ComboFix 11-06-05.01 - lqi 06/05/2011 12:43:42.1.2 - x64
    Microsoft® Windows Vista™ Business 6.0.6002.2.1252.1.1033.18.2967.1538 [GMT -4:00]
    Running from: c:\users\lqi\Desktop\ComboFix.exe
    AV: AntiVir Desktop *Disabled/Updated* {090F9C29-64CE-6C6F-379C-5901B49A85B7}
    SP: AntiVir Desktop *Disabled/Updated* {B26E7DCD-42F4-63E1-0D2C-6273CF1DCF0A}
    SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    .
    .
    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    C:\data
    c:\data\4type_bysession_5percent
    c:\data\aa
    c:\users\lqi\AppData\Roaming\Microsoft\Windows\Rec ent\ANTIGEN.exe
    c:\users\lqi\AppData\Roaming\Microsoft\Windows\Rec ent\CLSV.exe
    c:\users\lqi\AppData\Roaming\Microsoft\Windows\Rec ent\dudl.exe
    c:\users\lqi\AppData\Roaming\Microsoft\Windows\Rec ent\eb.dll
    c:\users\lqi\AppData\Roaming\Microsoft\Windows\Rec ent\energy.exe
    c:\users\lqi\AppData\Roaming\Microsoft\Windows\Rec ent\energy.sys
    c:\users\lqi\AppData\Roaming\Microsoft\Windows\Rec ent\fan.drv
    c:\users\lqi\AppData\Roaming\Microsoft\Windows\Rec ent\grid.tmp
    c:\users\lqi\AppData\Roaming\Microsoft\Windows\Rec ent\kernel32.drv
    c:\users\lqi\AppData\Roaming\Microsoft\Windows\Rec ent\kernel32.sys
    c:\users\lqi\AppData\Roaming\Microsoft\Windows\Rec ent\PE.dll
    c:\users\lqi\AppData\Roaming\Microsoft\Windows\Rec ent\PE.exe
    c:\users\lqi\AppData\Roaming\Microsoft\Windows\Rec ent\ppal.sys
    c:\users\lqi\AppData\Roaming\Microsoft\Windows\Rec ent\SICKBOY.drv
    c:\users\lqi\AppData\Roaming\Microsoft\Windows\Rec ent\SICKBOY.tmp
    c:\users\lqi\AppData\Roaming\Microsoft\Windows\Rec ent\SM.dll
    c:\users\lqi\AppData\Roaming\Microsoft\Windows\Rec ent\tjd.drv
    c:\users\lqi\AppData\Roaming\Microsoft\Windows\Rec ent\tjd.tmp
    c:\windows\system32\Thumbs.db
    Q:\AUTORUN.INF
    S:\AUTORUN.INF
    .
    .
    ((((((((((((((((((((((((( Files Created from 2011-05-05 to 2011-06-05 )))))))))))))))))))))))))))))))
    .
    .
    2011-06-05 17:03 . 2011-06-05 17:03 -------- d-----w- c:\users\Default\AppData\Local\temp
    2011-06-05 16:32 . 2011-06-05 16:32 -------- d-----w- c:\users\lqi\AppData\Local\{47A5C596-0B08-4769-A746-B16A23003106}
    2011-06-05 16:10 . 2011-06-05 16:10 -------- d-----w- c:\users\lqi\AppData\Local\{24B392F0-C4B7-449D-94AA-C89E95CE0462}
    2011-06-04 18:13 . 2011-06-04 18:13 -------- d-----w- c:\program files\iPod
    2011-06-04 18:13 . 2011-06-04 18:14 -------- d-----w- c:\program files\iTunes
    2011-06-04 18:08 . 2011-06-04 18:08 -------- d-----w- c:\program files\Bonjour
    2011-06-04 18:08 . 2011-06-04 18:08 -------- d-----w- c:\program files (x86)\Bonjour
    2011-06-04 14:07 . 2011-06-04 14:07 -------- d-----w- c:\users\lqi\AppData\Local\{47C613AD-D7AD-41CA-B28D-7BAE879DC7E7}
    2011-06-03 16:22 . 2011-04-01 21:07 83120 ----a-w- c:\windows\system32\drivers\avgntflt.sys
    2011-06-03 16:22 . 2011-04-01 21:07 116568 ----a-w- c:\windows\system32\drivers\avipbb.sys
    2011-06-03 16:22 . 2011-06-03 16:22 -------- d-----w- c:\programdata\Avira
    2011-06-03 16:22 . 2011-06-03 16:22 -------- d-----w- c:\program files (x86)\Avira
    2011-06-03 16:07 . 2011-05-09 22:00 8718160 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{1B5AFB27-65F2-4991-9128-B4545837DD54}\mpengine.dll
    2011-06-03 16:01 . 2011-06-03 16:01 -------- d-----w- c:\users\lqi\AppData\Local\{86012517-AA7B-47DA-BF15-62511678C91F}
    2011-06-02 15:48 . 2011-06-02 15:48 -------- d-----w- c:\programdata\SUPERAntiSpyware.com
    2011-06-02 14:51 . 2011-06-02 14:51 -------- d-sh--w- c:\programdata\PSRAYUJG
    2011-06-02 14:51 . 2011-06-02 16:39 -------- d-sh--w- c:\programdata\9c9680
    2011-06-02 14:08 . 2011-06-02 14:09 -------- d-----w- c:\users\lqi\AppData\Local\{F05907DF-7EDD-4423-856A-D0FF4380B98B}
    2011-06-01 22:33 . 2011-06-01 22:33 -------- d-----w- c:\users\lqi\AppData\Local\{2599A179-C367-462C-9D09-C9BE144C6151}
    2011-05-31 21:54 . 2011-05-31 21:55 -------- d-----w- c:\users\lqi\AppData\Local\{44B609B0-D76B-496D-AC23-F2683C36463E}
    2011-05-31 14:27 . 2011-05-31 14:27 -------- d-----w- c:\users\lqi\AppData\Local\{30974079-FCC4-4FEB-A28C-6686553205B4}
    2011-05-29 17:32 . 2011-05-29 17:32 -------- d-----w- c:\users\lqi\AppData\Local\{22AB9743-4382-4C46-9A18-DB1103E2C332}
    2011-05-28 17:43 . 2011-05-28 17:43 -------- d-----w- c:\users\lqi\AppData\Local\{3D83FBD6-96BA-49FE-90F2-57E21AED61F2}
    2011-05-27 21:03 . 2011-05-27 21:03 -------- d-----w- c:\users\lqi\AppData\Local\{6027B214-2254-41E9-BA0C-27EDBB51444D}
    2011-05-26 18:59 . 2011-05-26 18:59 -------- d-----w- c:\users\lqi\AppData\Local\{7FACE21B-7B07-4C40-9A7A-769005C6C280}
    2011-05-26 13:47 . 2011-05-26 13:47 -------- d-----w- c:\users\lqi\AppData\Local\{B5227B09-562F-4738-AB91-BCCFDAF356E0}
    2011-05-23 19:23 . 2011-05-23 19:23 -------- d-----w- c:\users\lqi\AppData\Local\{1C35662B-EB08-4FC4-B5C9-ACC7E4CD37DB}
    2011-05-21 18:23 . 2011-05-21 18:23 -------- d-----w- c:\users\lqi\AppData\Local\{70D9CF81-81CF-4274-9FCE-9B1C41CED19F}
    2011-05-20 15:44 . 2011-05-20 15:44 -------- d-----w- c:\users\lqi\AppData\Local\{71BFEB9D-7CE7-4F25-80D1-1E9647F96F97}
    2011-05-19 04:15 . 2011-05-19 04:15 -------- d-----w- c:\users\lqi\AppData\Local\{D5BF2E1A-A18A-4EC2-808C-1AE2298F7700}
    2011-05-18 15:09 . 2011-05-18 15:09 -------- d-----w- c:\users\lqi\AppData\Local\{F9116545-AC47-47C7-8346-7E6E6772E2F6}
    2011-05-17 22:01 . 2011-05-17 22:02 -------- d-----w- c:\users\lqi\AppData\Local\{846E8560-EBDA-41B6-AEDE-604BD85E5DBC}
    2011-05-17 03:12 . 2011-05-17 03:12 -------- d-----w- c:\users\lqi\AppData\Local\{DD24F0E7-5723-4A8E-9052-A220A2931623}
    2011-05-16 15:11 . 2011-05-16 15:11 -------- d-----w- c:\users\lqi\AppData\Local\{9FB0004E-AFAE-43E5-8351-63728D73657D}
    2011-05-15 16:41 . 2011-05-15 16:41 -------- d-----w- c:\users\lqi\AppData\Local\{07055C99-2753-4360-95E7-B07ED4C70AC7}
    2011-05-15 03:44 . 2011-05-15 03:44 -------- d-----w- c:\users\lqi\AppData\Local\{2D540C3C-8AEF-4377-AFB5-B39572D605C2}
    2011-05-12 21:47 . 2011-05-12 21:48 -------- d-----w- c:\users\lqi\AppData\Local\{73D5611E-8E72-4620-9274-F4D5B6F198CE}
    2011-05-12 00:31 . 2011-04-07 12:01 2409784 ----a-w- c:\program files (x86)\Windows Mail\OESpamFilter.dat
    2011-05-12 00:31 . 2011-04-07 12:02 2409784 ----a-w- c:\program files\Windows Mail\OESpamFilter.dat
    2011-05-12 00:17 . 2011-05-12 00:17 -------- d-----w- c:\users\lqi\AppData\Local\{DFD6E4D3-1B0D-4377-9CBB-E7F2087EDD6B}
    2011-05-10 02:04 . 2011-05-10 02:04 -------- d-----w- c:\users\lqi\AppData\Local\{7E60F79F-2C5A-4799-AECA-3ED34246ED6A}
    2011-05-09 23:17 . 2011-05-09 23:17 -------- d-----w- c:\users\lqi\AppData\Local\{84E3A561-CA30-4323-B7AF-D0CAF3217DEF}
    2011-05-07 14:54 . 2011-05-07 14:54 -------- d-----w- c:\users\lqi\AppData\Local\{DE6A09E6-6A1F-46F7-BC63-EAB0EFE6FA58}
    .
    .
    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) ))
    .
    2011-05-29 13:11 . 2010-08-05 06:44 25912 ----a-w- c:\windows\system32\drivers\mbam.sys
    2011-04-06 20:26 . 2011-04-06 20:26 96544 ----a-w- c:\windows\system32\dnssd.dll
    2011-04-06 20:26 . 2011-04-06 20:26 237856 ----a-w- c:\windows\system32\dnssdX.dll
    2011-04-06 20:26 . 2011-04-06 20:26 119584 ----a-w- c:\windows\system32\dns-sd.exe
    2011-04-06 20:20 . 2011-04-06 20:20 91424 ----a-w- c:\windows\SysWow64\dnssd.dll
    2011-04-06 20:20 . 2011-04-06 20:20 197920 ----a-w- c:\windows\SysWow64\dnssdX.dll
    2011-04-06 20:20 . 2011-04-06 20:20 107808 ----a-w- c:\windows\SysWow64\dns-sd.exe
    2011-03-12 22:52 . 2011-04-28 14:12 1653760 ----a-w- c:\windows\system32\XpsPrint.dll
    2011-03-12 21:55 . 2011-04-28 14:12 876032 ----a-w- c:\windows\SysWow64\XpsPrint.dll
    2011-03-11 19:32 . 2010-06-24 15:33 18328 ------w- c:\programdata\Microsoft\IdentityCRL\production\pp crlconfig600.dll
    2011-03-10 17:18 . 2011-04-15 22:04 1360384 ----a-w- c:\windows\system32\mfc42u.dll
    2011-03-10 17:18 . 2011-04-15 22:04 1398784 ----a-w- c:\windows\system32\mfc42.dll
    2011-03-10 17:03 . 2011-04-15 22:04 1162240 ----a-w- c:\windows\SysWow64\mfc42u.dll
    2011-03-10 17:03 . 2011-04-15 22:04 1136640 ----a-w- c:\windows\SysWow64\mfc42.dll
    .
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4
    .
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]
    "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1555968]
    "msnmsgr"="c:\program files (x86)\Windows Live\Messenger\msnmsgr.exe" [2010-11-10 4240760]
    "Messenger (Yahoo!)"="c:\progra~2\Yahoo!\Messenger\YahooMesse nger.exe" [2010-06-01 5252408]
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\ Windows\CurrentVersion\Run]
    "TPFNF7"="c:\program files (x86)\Lenovo\NPDIRECT\TPFNF7SP.exe" [2009-04-15 61728]
    "EZEJMNAP"="c:\progra~2\ThinkPad\UTILIT~1\EzEjMnAp .Exe" [2008-10-07 256576]
    "TVT Scheduler Proxy"="c:\program files (x86)\Common Files\Lenovo\Scheduler\scheduler_proxy.exe" [2008-05-24 487424]
    "LPManager"="c:\progra~2\THINKV~1\PrdCtr\LPMGR.exe " [2008-08-31 165208]
    "LPMailChecker"="c:\progra~2\THINKV~1\PrdCtr\LPMLC HK.exe" [2008-08-31 124248]
    "AMSG"="c:\program files (x86)\ThinkVantage\AMSG\Amsg.exe" [2009-03-19 461376]
    "CameraApplicationLauncher"="c:\program files (x86)\Lenovo\Camera Center\bin\CameraApplicationLaunchpadLauncher.exe" [2009-03-13 16384]
    "RoxioDragToDisc"="c:\program files (x86)\Lenovo2\Drag-to-Disc\DrgToDsc.exe" [2008-08-12 1116656]
    "PWMTRV"="c:\progra~2\ThinkPad\UTILIT~1\PWMTR64V.D LL" [2009-01-14 796448]
    "BLOG"="c:\progra~2\ThinkPad\UTILIT~1\BTVLogEx.DLL " [2009-01-14 214576]
    "CreateLMBCShortCut"="c:\program files (x86)\Lenovo\Mobile Broadband Connect\UserShortcutCreator.exe" [2009-05-15 40960]
    "ACTray"="c:\program files (x86)\ThinkPad\ConnectUtilities\ACTray.exe" [2009-07-10 435488]
    "ACWlIcon"="c:\program files (x86)\ThinkPad\ConnectUtilities\ACWlIcon.exe" [2009-07-10 177440]
    "GrooveMonitor"="c:\program files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
    "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
    "Adobe Acrobat Speed Launcher"="c:\program files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe" [2011-01-31 38840]
    "Acrobat Assistant 8.0"="c:\program files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe" [2010-09-22 640440]
    "Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-22 35760]
    "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288]
    "CarboniteSetupLite"="c:\program files (x86)\Carbonite\CarbonitePreinstaller.exe" [2009-08-04 318096]
    "MaxMenuMgr"="c:\program files (x86)\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe" [2009-09-26 185640]
    "QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2010-11-29 421888]
    "avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2011-03-28 281768]
    "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2011-04-27 421160]
    .
    c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
    Digital Line Detect.lnk - c:\program files (x86)\Digital Line Detect\DLG.exe [2009-8-5 50688]
    RCIMGDIR.exe.lnk - c:\program files (x86)\RotateImage\RCIMGDIR.exe [2009-8-5 55296]
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\policies\system]
    "EnableUIADesktopToggle"= 0 (0x0)
    .
    [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\ windows nt\currentversion\drivers32]
    "aux"=wdmaud.drv
    .
    R1 tvtumon;tvtumon;c:\windows\system32\DRIVERS\tvtumo n.sys [x]
    R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\ v4.0.30319\mscorsvw.exe [2010-03-18 130384]
    R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework6 4\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
    R2 LENOVO.MICMUTE;Lenovo Microphone Mute;c:\program files\LENOVO\HOTKEY\MICMUTE.exe [2009-05-21 45424]
    R2 TVT_UpdateMonitor;TVT Windows Update Monitor;c:\program files (x86)\Lenovo\Rescue and Recovery\UpdateMonitor.exe [2008-10-09 360448]
    R2 WebUpdate4;Web Update Wizard Service V4;c:\windows\SysWOW64\WebUpdateSvc4.exe [x]
    R3 ICDUSB3;ICDUSB3;c:\windows\system32\Drivers\ICDUSB 3.sys [x]
    R3 MosIrUsb;MosIrUsb.sys;c:\windows\system32\DRIVERS\ MosIrUsb.sys [x]
    R3 motccgp;Motorola USB Composite Device Driver;c:\windows\system32\DRIVERS\motccgp.sys [x]
    R3 motccgpfl;MotCcgpFlService;c:\windows\system32\DRI VERS\motccgpfl.sys [x]
    R3 MUXP;My WiFi PAN Mux-IM Protocol Driver;c:\windows\system32\DRIVERS\mux.sys [x]
    R3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe [2009-02-11 306688]
    R3 PSI;PSI;c:\windows\system32\DRIVERS\psi_mf.sys [x]
    R3 RoxMediaDB10;RoxMediaDB10;c:\program files (x86)\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe [2008-04-25 1120752]
    R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [x]
    R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework64\v4.0. 30319\WPF\WPFFontCache_v0400.exe [2010-03-18 1020768]
    S0 DRVECDB;DRVECDB;c:\windows\System32\Drivers\DRVECD B.SYS [x]
    S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHl pa64.sys [x]
    S0 TPDIGIMN;TPDIGIMN;c:\windows\System32\DRIVERS\ApsH M64.sys [x]
    S1 DLACDBHE;DLACDBHE;c:\windows\system32\Drivers\DLAC DBHE.SYS [x]
    S1 DLARTL_E;DLARTL_E;c:\windows\system32\Drivers\DLAR TL_E.SYS [x]
    S1 lenovo.smi;Lenovo System Interface Driver;c:\windows\system32\DRIVERS\smiifx64.sys [x]
    S2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [2011-03-28 136360]
    S2 DLABMFSE;DLABMFSE;c:\windows\system32\DLA\DLABMFSE .SYS [x]
    S2 DLABOIOE;DLABOIOE;c:\windows\system32\DLA\DLABOIOE .SYS [x]
    S2 DLADResE;DLADResE;c:\windows\system32\DLA\DLADResE .SYS [x]
    S2 DLAIFS_E;DLAIFS_E;c:\windows\system32\DLA\DLAIFS_E .SYS [x]
    S2 DLAOPIOE;DLAOPIOE;c:\windows\system32\DLA\DLAOPIOE .SYS [x]
    S2 DLAPoolE;DLAPoolE;c:\windows\system32\DLA\DLAPoolE .SYS [x]
    S2 DLAUDF_E;DLAUDF_E;c:\windows\system32\DLA\DLAUDF_E .SYS [x]
    S2 DLAUDFAE;DLAUDFAE;c:\windows\system32\DLA\DLAUDFAE .SYS [x]
    S2 DRVEDDM;DRVEDDM;c:\windows\system32\Drivers\DRVEDD M.SYS [x]
    S2 FreeAgentGoNext Service;Seagate Service;c:\program files (x86)\Seagate\SeagateManager\Sync\FreeAgentService .exe [2009-09-26 189736]
    S2 Power Manager DBC Service;Power Manager DBC Service;c:\program files (x86)\ThinkPad\Utilities\PWMDBSVC.EXE [2009-01-14 66848]
    S2 TPHKSVC;On Screen Display;c:\program files\LENOVO\HOTKEY\TPHKSVC.exe [2009-05-21 62320]
    S2 TVT Backup Protection Service;TVT Backup Protection Service;c:\program files (x86)\Lenovo\Rescue and Recovery\rrpservice.exe [2008-05-24 520192]
    S2 UNS;Intel(R) Active Management Technology User Notification Service;c:\program files (x86)\Common Files\Intel\Privacy Icon\UNS\UNS.exe [2008-05-29 2058776]
    S3 5U875UVC;Integrated Camera;c:\windows\system32\DRIVERS\5U875.sys [x]
    S3 CAXHWAZL;CAXHWAZL;c:\windows\system32\DRIVERS\CAXH WAZL.sys [x]
    S3 e1yexpress;Intel(R) Gigabit Network Connections Driver;c:\windows\system32\DRIVERS\e1y60x64.sys [x]
    S3 HECIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [x]
    S3 MUXMP;My WiFi PAN MUX-IM Virtual Miniport Driver;c:\windows\system32\DRIVERS\mux.sys [x]
    S3 NETw5v64;Intel(R) Wireless WiFi Link Adapter Driver for Windows Vista 64 Bit ;c:\windows\system32\DRIVERS\NETw5v64.sys [x]
    S3 Tp4Track;PS/2 TrackPoint Driver;c:\windows\system32\DRIVERS\tp4track.sys [x]
    S3 TVTI2C;Lenovo SM bus driver;c:\windows\system32\DRIVERS\Tvti2c.sys [x]
    .
    .
    Contents of the 'Scheduled Tasks' folder
    .
    2010-12-14 c:\windows\Tasks\PCDoctorBackgroundMonitorTask.job
    - c:\program files\PCDR5\pcdr5cuiw32.exe [2009-02-20 21:00]
    .
    .
    --------- x86-64 -----------
    .
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
    "combofix"="c:\combofix\CF17847.cfxxe" [X]
    "TrackPointSrv"="c:\program files\Lenovo\TrackPoint\tp4serv.exe" [2009-01-26 135968]
    "picon"="c:\program files (x86)\Common Files\Intel\Privacy Icon\PrivacyIconClient.exe" [2008-11-13 357400]
    "TpShocks"="TpShocks.exe" [2009-02-03 228640]
    "IntelWireless"="c:\program files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" [2009-02-11 1914880]
    "TPHOTKEY"="c:\program files\Lenovo\HOTKEY\TPOSDSVC.exe" [2009-03-13 68976]
    "LENOVO.TPFNF6R"="c:\program files\Lenovo\HOTKEY\TPFNF6R.exe" [2009-04-14 15136]
    "IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-09-17 151064]
    "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-09-17 209432]
    "Persistence"="c:\windows\system32\igfxpers.ex e" [2008-09-17 180560]
    "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-08-05 170496]
    "cssauth"="c:\program files\Lenovo\Client Security Solution\cssauth.exe" [2008-06-25 7253304]
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
    "LoadAppInit_DLLs"=0x1
    "AppInit_DLLs"=c:\windows\System32\acaptuser64 .dll
    .
    ------- Supplementary Scan -------
    .
    uLocal Page = c:\windows\system32\blank.htm
    uStart Page = hxxp://www.yahoo.com
    uDefault_Search_URL = hxxp://www.google.com/ie
    mLocal Page = c:\windows\SysWOW64\blank.htm
    uInternet Settings,ProxyOverride = *.local
    uSearchAssistant = hxxp://www.google.com/ie
    uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
    IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
    IE: Append Link Target to Existing PDF - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
    IE: Append to Existing PDF - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
    IE: Convert Link Target to Adobe PDF - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
    IE: Convert to Adobe PDF - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
    IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
    TCP: DhcpNameServer = 68.87.68.166 68.87.74.166
    TCP: Interfaces\{395AFEDA-7FBE-45D7-959C-3C3D7D883C12}: NameServer = 0.0.0.0
    DPF: {AC414988-E5BB-4C2C-873B-EA53D2F3D23A} - hxxp://t.live.cctv.com/ieocx/CCTVUpdateInstall.dll
    CLSID: {603d3801-bd81-11d0-a3a5-00c04fd706ec} - %SystemRoot%\SysWow64\browseui.dll
    FF - ProfilePath - c:\users\lqi\AppData\Roaming\Mozilla\Firefox\Profi les\d7tyfmwv.default\
    FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com
    FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
    FF - Ext: Java Console: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - c:\program files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
    FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
    FF - user.js: yahoo.ytff.general.dontshowhpoffer - true
    .
    - - - - ORPHANS REMOVED - - - -
    .
    HKLM-Run-Windows Defender - c:\program files (x86)\Windows Defender\MSASCui.exe
    AddRemove-Web Update Wizard (Redistributable) - c:\windows\system32\wuwuninst.exe
    .
    .
    .
    --------------------- LOCKED REGISTRY KEYS ---------------------
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CL SID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
    @Denied: (A 2) (Everyone)
    @="FlashBroker"
    "LocalizedString"="@c:\\Windows\\SysWOW64\\Macrome d\\Flash\\FlashUtil10p_ActiveX.exe,-101"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CL SID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
    "Enabled"=dword:00000001
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CL SID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUt il10p_ActiveX.exe"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CL SID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CL SID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
    @Denied: (A 2) (Everyone)
    @="Shockwave Flash Object"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CL SID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10 p.ocx"
    "ThreadingModel"="Apartment"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CL SID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
    @="0"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CL SID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
    @="ShockwaveFlash.ShockwaveFlash.10"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CL SID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10 p.ocx, 1"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CL SID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
    @="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CL SID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
    @="1.0"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CL SID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
    @="ShockwaveFlash.ShockwaveFlash"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CL SID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
    @Denied: (A 2) (Everyone)
    @="Macromedia Flash Factory Object"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CL SID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10 p.ocx"
    "ThreadingModel"="Apartment"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CL SID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
    @="FlashFactory.FlashFactory.1"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CL SID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10 p.ocx, 1"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CL SID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
    @="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CL SID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
    @="1.0"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CL SID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
    @="FlashFactory.FlashFactory"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\In terface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
    @Denied: (A 2) (Everyone)
    @="IFlashBroker4"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\In terface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
    @="{00020424-0000-0000-C000-000000000046}"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\In terface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
    "Version"="1.0"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Ty peLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}]
    @Denied: (A 2) (Everyone)
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Ty peLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}\1.0]
    @="Shockwave Flash"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Ty peLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}]
    @Denied: (A 2) (Everyone)
    @=""
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Ty peLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}\1.0]
    @="FlashBroker"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes]
    "SymbolicLinkValue"=hex(6):5c,00,52,00,45,00,47,00 ,49,00,53,00,54,00,52,00,59,
    00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00 ,5c,00,53,00,4f,00,46,00,\
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Cl ass\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
    @Denied: (A) (Users)
    @Denied: (A) (Everyone)
    @Allowed: (B 1 2 3 4 5) (S-1-5-20)
    "BlindDial"=dword:00000000
    .
    ------------------------ Other Running Processes ------------------------
    .
    c:\program files (x86)\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
    c:\program files (x86)\Avira\AntiVir Desktop\avguard.exe
    c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    c:\program files (x86)\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
    c:\program files (x86)\Bonjour\mDNSResponder.exe
    c:\program files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe
    c:\program files (x86)\Intel\AMT\LMS.exe
    c:\program files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe
    c:\program files (x86)\Common Files\Lenovo\tvt_reg_monitor_svc.exe
    c:\program files (x86)\Lenovo\Client Security Solution\tvttcsd.exe
    c:\program files (x86)\Lenovo\Rescue and Recovery\rrservice.exe
    c:\program files (x86)\Common Files\Lenovo\Scheduler\tvtsched.exe
    c:\program files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe
    c:\program files (x86)\ThinkPad\ConnectUtilities\AcSvc.exe
    c:\program files (x86)\Lenovo\System Update\SUService.exe
    c:\program files (x86)\ThinkPad\ConnectUtilities\SvcGuiHlpr.exe
    c:\program files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
    c:\program files\Lenovo\HOTKEY\TPONSCR.exe
    c:\program files\Lenovo\Zoom\TpScrex.exe
    c:\program files (x86)\ThinkPad\Utilities\EZEJMNAP.EXE
    c:\program files (x86)\ThinkVantage\PrdCtr\LPMGR.EXE
    c:\program files (x86)\ThinkVantage\PrdCtr\LPMLCHK.EXE
    c:\windows\SysWOW64\rundll32.exe
    c:\program files (x86)\Lenovo\Camera Center\bin\LenovoCameraCenter.exe
    c:\program files (x86)\Yahoo!\Messenger\ymsgr_tray.exe
    c:\progra~2\ThinkPad\UTILIT~1\PWMUIAux.exe
    .
    ************************************************** ************************
    .
    Completion time: 2011-06-05 13:35:31 - machine was rebooted
    ComboFix-quarantined-files.txt 2011-06-05 17:35
    .
    Pre-Run: 41,751,715,840 bytes free
    Post-Run: 41,214,369,792 bytes free
    .
    - - End Of File - - DC778CDCD34245602F9BB612B543E0E4

  7. #7
    broni is offline Senior Member
    Combofix log looks fine now.

    How is computer doing?

    Download TDSSKiller and save it to your desktop.
    • Extract (unzip) its contents to your desktop.
    • Open the TDSSKiller folder and doubleclick on TDSSKiller.exe to run the application, then on Start Scan.
    • If an infected file is detected, the default action will be Cure, click on Continue.
    • If a suspicious file is detected, the default action will be Skip, click on Continue.
    • It may ask you to reboot the computer to complete the process. Click on Reboot Now.
    • If no reboot is require, click on Report. A log file should appear. Please copy and paste the contents of that file here.
    • If a reboot is required, the report can also be found in your root directory (usually C:\ folder) in the form of TDSSKiller_xxxx_log.txt. Please copy and paste the contents of that file here.

  8. #8
    qili26 is offline Junior Member
    I'll try the TDSSKiller now. So should I select the "remove" option from Avira's message on C:\ComboFix\handle.cfxxe?

    Also, Find Gala kept redirecting my google search and this still happens now after the ComboFix run.

  9. #9
    qili26 is offline Junior Member
    Here is the TDSSKiller log results:

    2011/06/05 14:05:18.0089 5280 TDSS rootkit removing tool 2.5.3.0 May 25 2011 07:09:24
    2011/06/05 14:05:18.0822 5280 ================================================== ==============================
    2011/06/05 14:05:18.0822 5280 SystemInfo:
    2011/06/05 14:05:18.0822 5280
    2011/06/05 14:05:18.0822 5280 OS Version: 6.0.6002 ServicePack: 2.0
    2011/06/05 14:05:18.0822 5280 Product type: Workstation
    2011/06/05 14:05:18.0822 5280 ComputerName: LQI-PC
    2011/06/05 14:05:18.0822 5280 UserName: lqi
    2011/06/05 14:05:18.0822 5280 Windows directory: C:\Windows
    2011/06/05 14:05:18.0822 5280 System windows directory: C:\Windows
    2011/06/05 14:05:18.0822 5280 Running under WOW64
    2011/06/05 14:05:18.0822 5280 Processor architecture: Intel x64
    2011/06/05 14:05:18.0822 5280 Number of processors: 2
    2011/06/05 14:05:18.0822 5280 Page size: 0x1000
    2011/06/05 14:05:18.0822 5280 Boot type: Normal boot
    2011/06/05 14:05:18.0822 5280 ================================================== ==============================
    2011/06/05 14:05:19.0399 5280 Initialize success
    2011/06/05 14:05:38.0853 5588 ================================================== ==============================
    2011/06/05 14:05:38.0853 5588 Scan started
    2011/06/05 14:05:38.0853 5588 Mode: Manual;
    2011/06/05 14:05:38.0853 5588 ================================================== ==============================
    2011/06/05 14:05:39.0508 5588 5U875UVC (37086eab1d76b8b6d10251c2f5072836) C:\Windows\system32\DRIVERS\5U875.sys
    2011/06/05 14:05:39.0648 5588 ACPI (1965aaffab07e3fb03c77f81beba3547) C:\Windows\system32\drivers\acpi.sys
    2011/06/05 14:05:39.0851 5588 adp94xx (f14215e37cf124104575073f782111d2) C:\Windows\system32\drivers\adp94xx.sys
    2011/06/05 14:05:39.0991 5588 adpahci (7d05a75e3066861a6610f7ee04ff085c) C:\Windows\system32\drivers\adpahci.sys
    2011/06/05 14:05:40.0101 5588 adpu160m (820a201fe08a0c345b3bedbc30e1a77c) C:\Windows\system32\drivers\adpu160m.sys
    2011/06/05 14:05:40.0241 5588 adpu320 (9b4ab6854559dc168fbb4c24fc52e794) C:\Windows\system32\drivers\adpu320.sys
    2011/06/05 14:05:40.0381 5588 AFD (12415ccfd3e7cec55b5184e67b039fe4) C:\Windows\system32\drivers\afd.sys
    2011/06/05 14:05:40.0537 5588 agp440 (f6f6793b7f17b550ecfdbd3b229173f7) C:\Windows\system32\drivers\agp440.sys
    2011/06/05 14:05:40.0615 5588 aic78xx (222cb641b4b8a1d1126f8033f9fd6a00) C:\Windows\system32\drivers\djsvs.sys
    2011/06/05 14:05:40.0709 5588 aliide (f47743e97b2f4de6913038d7b14e7dd0) C:\Windows\system32\drivers\aliide.sys
    2011/06/05 14:05:40.0756 5588 amdide (695b3ea14709aa794ca6d13d5437d399) C:\Windows\system32\drivers\amdide.sys
    2011/06/05 14:05:40.0818 5588 AmdK8 (cdc3632a3a5ea4dbb83e46076a3165a1) C:\Windows\system32\drivers\amdk8.sys
    2011/06/05 14:05:41.0021 5588 arc (ba8417d4765f3988ff921f30f630e303) C:\Windows\system32\drivers\arc.sys
    2011/06/05 14:05:41.0099 5588 arcsas (9d41c435619733b34cc16a511e644b11) C:\Windows\system32\drivers\arcsas.sys
    2011/06/05 14:05:41.0177 5588 AsyncMac (22d13ff3dafec2a80634752b1eaa2de6) C:\Windows\system32\DRIVERS\asyncmac.sys
    2011/06/05 14:05:41.0239 5588 atapi (e68d9b3a3905619732f7fe039466a623) C:\Windows\system32\drivers\atapi.sys
    2011/06/05 14:05:41.0317 5588 avgntflt (39c2e2870fc0c2ae0595b883cbe716b4) C:\Windows\system32\DRIVERS\avgntflt.sys
    2011/06/05 14:05:41.0380 5588 avipbb (c98fa6e5ad0e857d22716bd2b8b1f399) C:\Windows\system32\DRIVERS\avipbb.sys
    2011/06/05 14:05:41.0536 5588 blbdrive (79feeb40056683f8f61398d81dda65d2) C:\Windows\system32\drivers\blbdrive.sys
    2011/06/05 14:05:41.0629 5588 bowser (2348447a80920b2493a9b582a23e81e1) C:\Windows\system32\DRIVERS\bowser.sys
    2011/06/05 14:05:41.0723 5588 BrFiltLo (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\drivers\brfiltlo.sys
    2011/06/05 14:05:41.0770 5588 BrFiltUp (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\drivers\brfiltup.sys
    2011/06/05 14:05:41.0848 5588 Brserid (f0f0ba4d815be446aa6a4583ca3bca9b) C:\Windows\system32\drivers\brserid.sys
    2011/06/05 14:05:41.0879 5588 BrSerWdm (a6eca2151b08a09caceca35c07f05b42) C:\Windows\system32\drivers\brserwdm.sys
    2011/06/05 14:05:41.0941 5588 BrUsbMdm (b79968002c277e869cf38bd22cd61524) C:\Windows\system32\drivers\brusbmdm.sys
    2011/06/05 14:05:42.0004 5588 BrUsbSer (a87528880231c54e75ea7a44943b38bf) C:\Windows\system32\drivers\brusbser.sys
    2011/06/05 14:05:42.0066 5588 BTHMODEM (e0777b34e05f8a82a21856efc900c29f) C:\Windows\system32\drivers\bthmodem.sys
    2011/06/05 14:05:42.0191 5588 CAXHWAZL (cd69e6640bc4778eb4159d34a707106e) C:\Windows\system32\DRIVERS\CAXHWAZL.sys
    2011/06/05 14:05:42.0269 5588 cdfs (b4d787db8d30793a4d4df9feed18f136) C:\Windows\system32\DRIVERS\cdfs.sys
    2011/06/05 14:05:42.0347 5588 cdrom (c025aa69be3d0d25c7a2e746ef6f94fc) C:\Windows\system32\DRIVERS\cdrom.sys
    2011/06/05 14:05:42.0425 5588 circlass (02ea568d498bbdd4ba55bf3fce34d456) C:\Windows\system32\drivers\circlass.sys
    2011/06/05 14:05:42.0503 5588 CLFS (3dca9a18b204939cfb24bea53e31eb48) C:\Windows\system32\CLFS.sys
    2011/06/05 14:05:42.0643 5588 CmBatt (b52d9a14ce4101577900a364ba86f3df) C:\Windows\system32\DRIVERS\CmBatt.sys
    2011/06/05 14:05:42.0675 5588 cmdide (7f1f812ac7adbead711d131f17c8ed77) C:\Windows\system32\drivers\cmdide.sys
    2011/06/05 14:05:42.0768 5588 CnxtHdAudService (b921e4b6483f225755d0e48654f7081f) C:\Windows\system32\drivers\CHDRT64.sys
    2011/06/05 14:05:42.0846 5588 Compbatt (7fb8ad01db0eabe60c8a861531a8f431) C:\Windows\system32\DRIVERS\compbatt.sys
    2011/06/05 14:05:42.0909 5588 crcdisk (a8585b6412253803ce8efcbd6d6dc15c) C:\Windows\system32\drivers\crcdisk.sys
    2011/06/05 14:05:43.0018 5588 CSC (f60f50c8ed3fcbe358430b95fe27d09c) C:\Windows\system32\drivers\csc.sys
    2011/06/05 14:05:43.0127 5588 DfsC (36cd31121f228e7e79bae60aa45764c6) C:\Windows\system32\Drivers\dfsc.sys
    2011/06/05 14:05:43.0267 5588 disk (b0107e40ecdb5fa692ebf832f295d905) C:\Windows\system32\drivers\disk.sys
    2011/06/05 14:05:43.0377 5588 DLABMFSE (c27713c1fc7c238d5021919d0011bc73) C:\Windows\system32\DLA\DLABMFSE.SYS
    2011/06/05 14:05:43.0423 5588 DLABOIOE (fb678e1538dd4fa4eacde8ea2e6d23f5) C:\Windows\system32\DLA\DLABOIOE.SYS
    2011/06/05 14:05:43.0455 5588 DLACDBHE (8bffdf668b5b3db82b45fd98f6d5b047) C:\Windows\system32\Drivers\DLACDBHE.SYS
    2011/06/05 14:05:43.0486 5588 DLADResE (b8fc01714306cdced91f4c8e8a5f9959) C:\Windows\system32\DLA\DLADResE.SYS
    2011/06/05 14:05:43.0517 5588 DLAIFS_E (a21ca4b265f02df355b23d1880a47b0a) C:\Windows\system32\DLA\DLAIFS_E.SYS
    2011/06/05 14:05:43.0548 5588 DLAOPIOE (0473e600175aaa7a94f7105bd51501d5) C:\Windows\system32\DLA\DLAOPIOE.SYS
    2011/06/05 14:05:43.0579 5588 DLAPoolE (926a191652c52f8c29945d4fbcc342f3) C:\Windows\system32\DLA\DLAPoolE.SYS
    2011/06/05 14:05:43.0642 5588 DLARTL_E (c8129d9fcd1e8d24beaa0a65a8e70c40) C:\Windows\system32\Drivers\DLARTL_E.SYS
    2011/06/05 14:05:43.0673 5588 DLAUDFAE (85dbe7478171b973d3a485cbc8aa5a8a) C:\Windows\system32\DLA\DLAUDFAE.SYS
    2011/06/05 14:05:43.0704 5588 DLAUDF_E (27dca215bb399ea472b4277664aebd8c) C:\Windows\system32\DLA\DLAUDF_E.SYS
    2011/06/05 14:05:43.0798 5588 dot4 (74c02b1717740c3b8039539e23e4b53f) C:\Windows\system32\DRIVERS\Dot4.sys
    2011/06/05 14:05:43.0829 5588 Dot4Print (08321d1860235bf42cf2854234337aea) C:\Windows\system32\DRIVERS\Dot4Prt.sys
    2011/06/05 14:05:43.0860 5588 dot4usb (4adccf0124f2b6911d3786a5d0e779e5) C:\Windows\system32\DRIVERS\dot4usb.sys
    2011/06/05 14:05:43.0969 5588 drmkaud (f1a78a98cfc2ee02144c6bec945447e6) C:\Windows\system32\drivers\drmkaud.sys
    2011/06/05 14:05:44.0016 5588 DRVECDB (401b92f84c65b05302a2c0b29c7a40f1) C:\Windows\system32\Drivers\DRVECDB.SYS
    2011/06/05 14:05:44.0032 5588 DRVEDDM (20c296250f155e60b16a3b4601d28695) C:\Windows\system32\Drivers\DRVEDDM.SYS
    2011/06/05 14:05:44.0110 5588 DXGKrnl (b8e554e502d5123bc111f99d6a2181b4) C:\Windows\System32\drivers\dxgkrnl.sys
    2011/06/05 14:05:44.0203 5588 e1express (17d40652ef3e55eeae187a89df40965a) C:\Windows\system32\DRIVERS\e1e6032e.sys
    2011/06/05 14:05:44.0281 5588 E1G60 (264cee7b031a9d6c827f3d0cb031f2fe) C:\Windows\system32\DRIVERS\E1G6032E.sys
    2011/06/05 14:05:44.0391 5588 e1yexpress (d608110adb132e683360fca0f6b2bb53) C:\Windows\system32\DRIVERS\e1y60x64.sys
    2011/06/05 14:05:44.0500 5588 Ecache (5f94962be5a62db6e447ff6470c4f48a) C:\Windows\system32\drivers\ecache.sys
    2011/06/05 14:05:44.0547 5588 elxstor (c4636d6e10469404ab5308d9fd45ed07) C:\Windows\system32\drivers\elxstor.sys
    2011/06/05 14:05:44.0609 5588 ErrDev (bc3a58e938bb277e46bf4b3003b01abd) C:\Windows\system32\drivers\errdev.sys
    2011/06/05 14:05:44.0718 5588 exfat (486844f47b6636044a42454614ed4523) C:\Windows\system32\drivers\exfat.sys
    2011/06/05 14:05:44.0749 5588 fastfat (1a4bee34277784619ddaf0422c0c6e23) C:\Windows\system32\drivers\fastfat.sys
    2011/06/05 14:05:44.0827 5588 fdc (81b79b6df71fa1d2c6d688d830616e39) C:\Windows\system32\DRIVERS\fdc.sys
    2011/06/05 14:05:44.0859 5588 FileInfo (457b7d1d533e4bd62a99aed9c7bb4c59) C:\Windows\system32\drivers\fileinfo.sys
    2011/06/05 14:05:44.0890 5588 Filetrace (d421327fd6efccaf884a54c58e1b0d7f) C:\Windows\system32\drivers\filetrace.sys
    2011/06/05 14:05:44.0968 5588 flpydisk (230923ea2b80f79b0f88d90f87b87ebd) C:\Windows\system32\DRIVERS\flpydisk.sys
    2011/06/05 14:05:45.0015 5588 FltMgr (e3041bc26d6930d61f42aedb79c91720) C:\Windows\system32\drivers\fltmgr.sys
    2011/06/05 14:05:45.0124 5588 Fs_Rec (29d99e860a1ca0a03c6a733fdd0da703) C:\Windows\system32\drivers\Fs_Rec.sys
    2011/06/05 14:05:45.0186 5588 gagp30kx (c8e416668d3dc2be3d4fe4c79224997f) C:\Windows\system32\drivers\gagp30kx.sys
    2011/06/05 14:05:45.0280 5588 GEARAspiWDM (e403aacf8c7bb11375122d2464560311) C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
    2011/06/05 14:05:45.0373 5588 HdAudAddService (df45f8142dc6df9d18c39b3effbd0409) C:\Windows\system32\drivers\HdAudio.sys
    2011/06/05 14:05:45.0451 5588 HDAudBus (f942c5820205f2fb453243edfec82a3d) C:\Windows\system32\DRIVERS\HDAudBus.sys
    2011/06/05 14:05:45.0561 5588 HECIx64 (c936f49f1da1f4cc9eebcd805abc2bba) C:\Windows\system32\DRIVERS\HECIx64.sys
    2011/06/05 14:05:45.0607 5588 HidBth (b4881c84a180e75b8c25dc1d726c375f) C:\Windows\system32\drivers\hidbth.sys
    2011/06/05 14:05:45.0639 5588 HidIr (4e77a77e2c986e8f88f996bb3e1ad829) C:\Windows\system32\drivers\hidir.sys
    2011/06/05 14:05:45.0732 5588 HidUsb (443bdd2d30bb4f00795c797e2cf99edf) C:\Windows\system32\DRIVERS\hidusb.sys
    2011/06/05 14:05:45.0810 5588 HpCISSs (d7109a1e6bd2dfdbcba72a6bc626a13b) C:\Windows\system32\drivers\hpcisss.sys
    2011/06/05 14:05:45.0888 5588 HSFHWAZL (57ba73b5b321291e5114cb21350e1ea0) C:\Windows\system32\DRIVERS\VSTAZL6.SYS
    2011/06/05 14:05:45.0982 5588 HSF_DPV (ebdba99c2362457be429f024396b63be) C:\Windows\system32\DRIVERS\CAX_DPV.sys
    2011/06/05 14:05:46.0091 5588 HTTP (098f1e4e5c9cb5b0063a959063631610) C:\Windows\system32\drivers\HTTP.sys
    2011/06/05 14:05:46.0185 5588 i2omp (da94c854cea5fac549d4e1f6e88349e8) C:\Windows\system32\drivers\i2omp.sys
    2011/06/05 14:05:46.0247 5588 i8042prt (cbb597659a2713ce0c9cc20c88c7591f) C:\Windows\system32\DRIVERS\i8042prt.sys
    2011/06/05 14:05:46.0341 5588 iaStor (1adaa4f16073fd0c7270f451fd024e97) C:\Windows\system32\DRIVERS\iaStor.sys
    2011/06/05 14:05:46.0372 5588 iaStorV (3e3bf3627d886736d0b4e90054f929f6) C:\Windows\system32\drivers\iastorv.sys
    2011/06/05 14:05:46.0434 5588 IBMPMDRV (287c219b595dc73f2fcdc0e9d172c711) C:\Windows\system32\DRIVERS\ibmpmdrv.sys
    2011/06/05 14:05:46.0497 5588 ICDUSB3 (55836a07c030748b47c613dc30f724d5) C:\Windows\system32\Drivers\ICDUSB3.sys
    2011/06/05 14:05:46.0777 5588 igfx (ea58016577eac334f9eb402bfbdfb740) C:\Windows\system32\DRIVERS\igdkmd64.sys
    2011/06/05 14:05:47.0058 5588 iirsp (8c3951ad2fe886ef76c7b5027c3125d3) C:\Windows\system32\drivers\iirsp.sys
    2011/06/05 14:05:47.0105 5588 intelide (c26e78eb76be83a8568ceb964cd64111) C:\Windows\system32\drivers\intelide.sys
    2011/06/05 14:05:47.0136 5588 intelppm (bfd84af32fa1bad6231c4585cb469630) C:\Windows\system32\DRIVERS\intelppm.sys
    2011/06/05 14:05:47.0199 5588 IpFilterDriver (d8aabc341311e4780d6fce8c73c0ad81) C:\Windows\system32\DRIVERS\ipfltdrv.sys
    2011/06/05 14:05:47.0292 5588 IPMIDRV (9c2ee2e6e5a7203bfae15c299475ec67) C:\Windows\system32\drivers\ipmidrv.sys
    2011/06/05 14:05:47.0339 5588 IPNAT (b7e6212f581ea5f6ab0c3a6ceeeb89be) C:\Windows\system32\DRIVERS\ipnat.sys
    2011/06/05 14:05:47.0417 5588 irda (86583188c7157ffda249529423fc3e6f) C:\Windows\system32\DRIVERS\irda.sys
    2011/06/05 14:05:47.0448 5588 IRENUM (8c42ca155343a2f11d29feca67faa88d) C:\Windows\system32\drivers\irenum.sys
    2011/06/05 14:05:47.0542 5588 isapnp (0672bfcedc6fc468a2b0500d81437f4f) C:\Windows\system32\drivers\isapnp.sys
    2011/06/05 14:05:47.0620 5588 iScsiPrt (e4fdf99599f27ec25d2cf6d754243520) C:\Windows\system32\DRIVERS\msiscsi.sys
    2011/06/05 14:05:47.0667 5588 iteatapi (63c766cdc609ff8206cb447a65abba4a) C:\Windows\system32\drivers\iteatapi.sys
    2011/06/05 14:05:47.0745 5588 iteraid (1281fe73b17664631d12f643cbea3f59) C:\Windows\system32\drivers\iteraid.sys
    2011/06/05 14:05:47.0807 5588 kbdclass (423696f3ba6472dd17699209b933bc26) C:\Windows\system32\DRIVERS\kbdclass.sys
    2011/06/05 14:05:47.0854 5588 kbdhid (dbdf75d51464fbc47d0104ec3d572c05) C:\Windows\system32\DRIVERS\kbdhid.sys
    2011/06/05 14:05:47.0947 5588 KSecDD (476e2c1dcea45895994bef11c2a98715) C:\Windows\system32\Drivers\ksecdd.sys
    2011/06/05 14:05:48.0010 5588 ksthunk (1d419cf43db29396ecd7113d129d94eb) C:\Windows\system32\drivers\ksthunk.sys
    2011/06/05 14:05:48.0119 5588 lenovo.smi (5acff5823634bc2c4ebf559c3b33e18e) C:\Windows\system32\DRIVERS\smiifx64.sys
    2011/06/05 14:05:48.0150 5588 lltdio (96ece2659b6654c10a0c310ae3a6d02c) C:\Windows\system32\DRIVERS\lltdio.sys
    2011/06/05 14:05:48.0213 5588 LSI_FC (acbe1af32d3123e330a07bfbc5ec4a9b) C:\Windows\system32\drivers\lsi_fc.sys
    2011/06/05 14:05:48.0291 5588 LSI_SAS (799ffb2fc4729fa46d2157c0065b3525) C:\Windows\system32\drivers\lsi_sas.sys
    2011/06/05 14:05:48.0322 5588 LSI_SCSI (f445ff1daad8a226366bfaf42551226b) C:\Windows\system32\drivers\lsi_scsi.sys
    2011/06/05 14:05:48.0353 5588 luafv (52f87b9cc8932c2a7375c3b2a9be5e3e) C:\Windows\system32\drivers\luafv.sys
    2011/06/05 14:05:48.0400 5588 mdmxsdk (e4f44ec214b3e381e1fc844a02926666) C:\Windows\system32\DRIVERS\mdmxsdk.sys
    2011/06/05 14:05:48.0478 5588 megasas (5c5cd6aaced32fb26c3fb34b3dcf972f) C:\Windows\system32\drivers\megasas.sys
    2011/06/05 14:05:48.0571 5588 MegaSR (859bc2436b076c77c159ed694acfe8f8) C:\Windows\system32\drivers\megasr.sys
    2011/06/05 14:05:48.0634 5588 Modem (59848d5cc74606f0ee7557983bb73c2e) C:\Windows\system32\drivers\modem.sys
    2011/06/05 14:05:48.0712 5588 monitor (c247cc2a57e0a0c8c6dccf7807b3e9e5) C:\Windows\system32\DRIVERS\monitor.sys
    2011/06/05 14:05:48.0774 5588 MosIrUsb (54f44c3a4f6c1c4d00d4157fbd531eb1) C:\Windows\system32\DRIVERS\MosIrUsb.sys
    2011/06/05 14:05:48.0821 5588 motccgp (7bd101253058db30c52c6ea8d3911754) C:\Windows\system32\DRIVERS\motccgp.sys
    2011/06/05 14:05:48.0852 5588 motccgpfl (1a700e7063ca7f2b29a4e761da604dfb) C:\Windows\system32\DRIVERS\motccgpfl.sys
    2011/06/05 14:05:48.0899 5588 mouclass (9367304e5e412b120cf5f4ea14e4e4f1) C:\Windows\system32\DRIVERS\mouclass.sys
    2011/06/05 14:05:48.0977 5588 mouhid (c2c2bd5c5ce5aaf786ddd74b75d2ac69) C:\Windows\system32\DRIVERS\mouhid.sys
    2011/06/05 14:05:49.0008 5588 MountMgr (11bc9b1e8801b01f7f6adb9ead30019b) C:\Windows\system32\drivers\mountmgr.sys
    2011/06/05 14:05:49.0039 5588 mpio (f8276eb8698142884498a528dfea8478) C:\Windows\system32\drivers\mpio.sys
    2011/06/05 14:05:49.0086 5588 mpsdrv (c92b9abdb65a5991e00c28f13491dba2) C:\Windows\system32\drivers\mpsdrv.sys
    2011/06/05 14:05:49.0133 5588 Mraid35x (3c200630a89ef2c0864d515b7a75802e) C:\Windows\system32\drivers\mraid35x.sys
    2011/06/05 14:05:49.0180 5588 MRxDAV (7c1de4aa96dc0c071611f9e7de02a68d) C:\Windows\system32\drivers\mrxdav.sys
    2011/06/05 14:05:49.0305 5588 mrxsmb (dc434b4769e18da09ce1b7755d4c64e9) C:\Windows\system32\DRIVERS\mrxsmb.sys
    2011/06/05 14:05:49.0367 5588 mrxsmb10 (64713fcfe3de8881d62f8f3f2f794241) C:\Windows\system32\DRIVERS\mrxsmb10.sys
    2011/06/05 14:05:49.0445 5588 mrxsmb20 (0005c599a2abf767a815afcd32e523e3) C:\Windows\system32\DRIVERS\mrxsmb20.sys
    2011/06/05 14:05:49.0554 5588 msahci (e7136685c4e3acdb3b9d87ca23e03947) C:\Windows\system32\drivers\msahci.sys
    2011/06/05 14:05:49.0585 5588 msdsm (264bbb4aaf312a485f0e44b65a6b7202) C:\Windows\system32\drivers\msdsm.sys
    2011/06/05 14:05:49.0632 5588 Msfs (704f59bfc4512d2bb0146aec31b10a7c) C:\Windows\system32\drivers\Msfs.sys
    2011/06/05 14:05:49.0710 5588 msisadrv (00ebc952961664780d43dca157e79b27) C:\Windows\system32\drivers\msisadrv.sys
    2011/06/05 14:05:49.0819 5588 MSKSSRV (0ea73e498f53b96d83dbfca074ad4cf8) C:\Windows\system32\drivers\MSKSSRV.sys
    2011/06/05 14:05:49.0835 5588 MSPCLOCK (52e59b7e992a58e740aa63f57edbae8b) C:\Windows\system32\drivers\MSPCLOCK.sys
    2011/06/05 14:05:49.0882 5588 MSPQM (49084a75bae043ae02d5b44d02991bb2) C:\Windows\system32\drivers\MSPQM.sys
    2011/06/05 14:05:49.0944 5588 MsRPC (dc6ccf440cdede4293db41c37a5060a5) C:\Windows\system32\drivers\MsRPC.sys
    2011/06/05 14:05:50.0007 5588 mssmbios (855796e59df77ea93af46f20155bf55b) C:\Windows\system32\DRIVERS\mssmbios.sys
    2011/06/05 14:05:50.0085 5588 MSTEE (86d632d75d05d5b7c7c043fa3564ae86) C:\Windows\system32\drivers\MSTEE.sys
    2011/06/05 14:05:50.0131 5588 Mup (0cc49f78d8aca0877d885f149084e543) C:\Windows\system32\Drivers\mup.sys
    2011/06/05 14:05:50.0209 5588 MUXMP (95027ec510ae3e67c4ab103ae544737e) C:\Windows\system32\DRIVERS\mux.sys
    2011/06/05 14:05:50.0256 5588 MUXP (95027ec510ae3e67c4ab103ae544737e) C:\Windows\system32\DRIVERS\mux.sys
    2011/06/05 14:05:50.0365 5588 NativeWifiP (2007b826c4acd94ae32232b41f0842b9) C:\Windows\system32\DRIVERS\nwifi.sys
    2011/06/05 14:05:50.0459 5588 NDIS (65950e07329fcee8e6516b17c8d0abb6) C:\Windows\system32\drivers\ndis.sys
    2011/06/05 14:05:50.0521 5588 NdisTapi (64df698a425478e321981431ac171334) C:\Windows\system32\DRIVERS\ndistapi.sys
    2011/06/05 14:05:50.0553 5588 Ndisuio (8baa43196d7b5bb972c9a6b2bbf61a19) C:\Windows\system32\DRIVERS\ndisuio.sys
    2011/06/05 14:05:50.0584 5588 NdisWan (f8158771905260982ce724076419ef19) C:\Windows\system32\DRIVERS\ndiswan.sys
    2011/06/05 14:05:50.0615 5588 NDProxy (9cb77ed7cb72850253e973a2d6afdf49) C:\Windows\system32\drivers\NDProxy.sys
    2011/06/05 14:05:50.0662 5588 NetBIOS (a499294f5029a7862adc115bda7371ce) C:\Windows\system32\DRIVERS\netbios.sys
    2011/06/05 14:05:50.0693 5588 netbt (fc2c792ebddc8e28df939d6a92c83d61) C:\Windows\system32\DRIVERS\netbt.sys
    2011/06/05 14:05:50.0865 5588 NETw5v64 (4b953e6cb07830ff4e236e02cc264d4c) C:\Windows\system32\DRIVERS\NETw5v64.sys
    2011/06/05 14:05:51.0099 5588 nfrd960 (4ac08bd6af2df42e0c3196d826c8aea7) C:\Windows\system32\drivers\nfrd960.sys
    2011/06/05 14:05:51.0161 5588 Npfs (b298874f8e0ea93f06ec40aa8d146478) C:\Windows\system32\drivers\Npfs.sys
    2011/06/05 14:05:51.0177 5588 nsiproxy (1523af19ee8b030ba682f7a53537eaeb) C:\Windows\system32\drivers\nsiproxy.sys
    2011/06/05 14:05:51.0286 5588 Ntfs (bac869dfb98e499ba4d9bb1fb43270e1) C:\Windows\system32\drivers\Ntfs.sys
    2011/06/05 14:05:51.0411 5588 Null (dd5d684975352b85b52e3fd5347c20cb) C:\Windows\system32\drivers\Null.sys
    2011/06/05 14:05:51.0457 5588 nvraid (2c040b7ada5b06f6facadac8514aa034) C:\Windows\system32\drivers\nvraid.sys
    2011/06/05 14:05:51.0489 5588 nvstor (f7ea0fe82842d05eda3efdd376dbfdba) C:\Windows\system32\drivers\nvstor.sys
    2011/06/05 14:05:51.0520 5588 nv_agp (19067ca93075ef4823e3938a686f532f) C:\Windows\system32\drivers\nv_agp.sys
    2011/06/05 14:05:51.0645 5588 ohci1394 (1b30103fde512915a9214b108b6e7a9c) C:\Windows\system32\DRIVERS\ohci1394.sys
    2011/06/05 14:05:51.0707 5588 Parport (aecd57f94c887f58919f307c35498ea0) C:\Windows\system32\drivers\parport.sys
    2011/06/05 14:05:51.0754 5588 partmgr (f9b5eda4c17a2be7663f064dbf0fe254) C:\Windows\system32\drivers\partmgr.sys
    2011/06/05 14:05:51.0816 5588 pci (47ab1e0fc9d0e12bb53ba246e3a0906d) C:\Windows\system32\drivers\pci.sys
    2011/06/05 14:05:51.0894 5588 pciide (2657f6c0b78c36d95034be109336e382) C:\Windows\system32\drivers\pciide.sys
    2011/06/05 14:05:51.0972 5588 pcmcia (a2d6b9c3f532baa27cb0c158d8ef4da6) C:\Windows\system32\DRIVERS\pcmcia.sys
    2011/06/05 14:05:52.0035 5588 PEAUTH (58865916f53592a61549b04941bfd80d) C:\Windows\system32\drivers\peauth.sys
    2011/06/05 14:05:52.0222 5588 PptpMiniport (23386e9952025f5f21c368971e2e7301) C:\Windows\system32\DRIVERS\raspptp.sys
    2011/06/05 14:05:52.0315 5588 Processor (5080e59ecee0bc923f14018803aa7a01) C:\Windows\system32\drivers\processr.sys
    2011/06/05 14:05:52.0409 5588 psadd (6b99a6e750c113cfbe766769c4ce7227) C:\Windows\system32\DRIVERS\psadd.sys
    2011/06/05 14:05:52.0456 5588 PSched (c5ab7f0809392d0da027f4a2a81bfa31) C:\Windows\system32\DRIVERS\pacer.sys
    2011/06/05 14:05:52.0534 5588 PSI (b490d659791ab9dd83328541ebc4ef33) C:\Windows\system32\DRIVERS\psi_mf.sys
    2011/06/05 14:05:52.0596 5588 PxHlpa64 (fbf4db6d53585437e41a113300002a2b) C:\Windows\system32\Drivers\PxHlpa64.sys
    2011/06/05 14:05:52.0659 5588 ql2300 (0b83f4e681062f3839be2ec1d98fd94a) C:\Windows\system32\drivers\ql2300.sys
    2011/06/05 14:05:52.0737 5588 ql40xx (e1c80f8d4d1e39ef9595809c1369bf2a) C:\Windows\system32\drivers\ql40xx.sys
    2011/06/05 14:05:52.0783 5588 QWAVEdrv (e8d76edab77ec9c634c27b8eac33adc5) C:\Windows\system32\drivers\qwavedrv.sys
    2011/06/05 14:05:52.0815 5588 RasAcd (1013b3b663a56d3ddd784f581c1bd005) C:\Windows\system32\DRIVERS\rasacd.sys
    2011/06/05 14:05:52.0861 5588 Rasl2tp (ac7bc4d42a7e558718dfdec599bbfc2c) C:\Windows\system32\DRIVERS\rasl2tp.sys
    2011/06/05 14:05:52.0924 5588 RasPppoe (4517fbf8b42524afe4ede1de102aae3e) C:\Windows\system32\DRIVERS\raspppoe.sys
    2011/06/05 14:05:52.0955 5588 RasSstp (c6a593b51f34c33e5474539544072527) C:\Windows\system32\DRIVERS\rassstp.sys
    2011/06/05 14:05:52.0986 5588 rdbss (322db5c6b55e8d8ee8d6f358b2aaabb1) C:\Windows\system32\DRIVERS\rdbss.sys
    2011/06/05 14:05:53.0033 5588 RDPCDD (603900cc05f6be65ccbf373800af3716) C:\Windows\system32\DRIVERS\RDPCDD.sys
    2011/06/05 14:05:53.0095 5588 rdpdr (ae23e79b13feb62939e2ca1189e71735) C:\Windows\system32\DRIVERS\rdpdr.sys
    2011/06/05 14:05:53.0127 5588 RDPENCDD (cab9421daf3d97b33d0d055858e2c3ab) C:\Windows\system32\drivers\rdpencdd.sys
    2011/06/05 14:05:53.0189 5588 RDPWD (b1d741c87cea8d7282146366cc9c3f81) C:\Windows\system32\drivers\RDPWD.sys
    2011/06/05 14:05:53.0267 5588 rspndr (22a9cb08b1a6707c1550c6bf099aae73) C:\Windows\system32\DRIVERS\rspndr.sys
    2011/06/05 14:05:53.0298 5588 sbp2port (cd9c693589c60ad59bbbcfb0e524e01b) C:\Windows\system32\drivers\sbp2port.sys
    2011/06/05 14:05:53.0345 5588 sdbus (b42ee50f7d24f837f925332eb349eca5) C:\Windows\system32\DRIVERS\sdbus.sys
    2011/06/05 14:05:53.0376 5588 secdrv (3ea8a16169c26afbeb544e0e48421186) C:\Windows\system32\drivers\secdrv.sys
    2011/06/05 14:05:53.0407 5588 Serenum (f71bfe7ac6c52273b7c82cbf1bb2a222) C:\Windows\system32\DRIVERS\serenum.sys
    2011/06/05 14:05:53.0439 5588 Serial (e62fac91ee288db29a9696a9d279929c) C:\Windows\system32\DRIVERS\serial.sys
    2011/06/05 14:05:53.0470 5588 sermouse (a842f04833684bceea7336211be478df) C:\Windows\system32\drivers\sermouse.sys
    2011/06/05 14:05:53.0517 5588 sffdisk (14d4b4465193a87c127933978e8c4106) C:\Windows\system32\drivers\sffdisk.sys
    2011/06/05 14:05:53.0548 5588 sffp_mmc (7073aee3f82f3d598e3825962aa98ab2) C:\Windows\system32\drivers\sffp_mmc.sys
    2011/06/05 14:05:53.0563 5588 sffp_sd (35e59ebe4a01a0532ed67975161c7b82) C:\Windows\system32\drivers\sffp_sd.sys
    2011/06/05 14:05:53.0610 5588 sfloppy (40567781f0785c4a69411d1b40da8987) C:\Windows\system32\DRIVERS\sfloppy.sys
    2011/06/05 14:05:53.0719 5588 Shockprf (e3b2d8fb86c3d92a2832b8e196f105da) C:\Windows\system32\DRIVERS\Apsx64.sys
    2011/06/05 14:05:53.0751 5588 SiSRaid2 (7a5de502aeb719d4594c6471060a78b3) C:\Windows\system32\drivers\sisraid2.sys
    2011/06/05 14:05:53.0782 5588 SiSRaid4 (3a2f769fab9582bc720e11ea1dfb184d) C:\Windows\system32\drivers\sisraid4.sys
    2011/06/05 14:05:53.0829 5588 Smb (290b6f6a0ec4fcdfc90f5cb6d7020473) C:\Windows\system32\DRIVERS\smb.sys
    2011/06/05 14:05:53.0891 5588 spldr (386c3c63f00a7040c7ec5e384217e89d) C:\Windows\system32\drivers\spldr.sys
    2011/06/05 14:05:53.0969 5588 srv (880a57fccb571ebd063d4dd50e93e46d) C:\Windows\system32\DRIVERS\srv.sys
    2011/06/05 14:05:54.0031 5588 srv2 (fa36d119249bf27bc4c0079734e1f33b) C:\Windows\system32\DRIVERS\srv2.sys
    2011/06/05 14:05:54.0078 5588 srvnet (cfe7bc92d52c7e79427545909a0182f8) C:\Windows\system32\DRIVERS\srvnet.sys
    2011/06/05 14:05:54.0219 5588 swenum (8a851ca908b8b974f89c50d2e18d4f0c) C:\Windows\system32\DRIVERS\swenum.sys
    2011/06/05 14:05:54.0250 5588 Symc8xx (2f26a2c6fc96b29beff5d8ed74e6625b) C:\Windows\system32\drivers\symc8xx.sys
    2011/06/05 14:05:54.0297 5588 Sym_hi (a909667976d3bccd1df813fed517d837) C:\Windows\system32\drivers\sym_hi.sys
    2011/06/05 14:05:54.0343 5588 Sym_u3 (36887b56ec2d98b9c362f6ae4de5b7b0) C:\Windows\system32\drivers\sym_u3.sys
    2011/06/05 14:05:54.0468 5588 Tcpip (973658a2ea9c06b2976884b9046dfc6c) C:\Windows\system32\drivers\tcpip.sys
    2011/06/05 14:05:54.0577 5588 Tcpip6 (973658a2ea9c06b2976884b9046dfc6c) C:\Windows\system32\DRIVERS\tcpip.sys
    2011/06/05 14:05:54.0655 5588 tcpipreg (c7e72a4071ee0200e3c075dacfb2b334) C:\Windows\system32\drivers\tcpipreg.sys
    2011/06/05 14:05:54.0718 5588 TDPIPE (1d8bf4aaa5fb7a2761475781dc1195bc) C:\Windows\system32\drivers\tdpipe.sys
    2011/06/05 14:05:54.0749 5588 TDTCP (7f7e00cdf609df657f4cda02dd1c9bb1) C:\Windows\system32\drivers\tdtcp.sys
    2011/06/05 14:05:54.0796 5588 tdx (458919c8c42e398dc4802178d5ffee27) C:\Windows\system32\DRIVERS\tdx.sys
    2011/06/05 14:05:54.0858 5588 TermDD (8c19678d22649ec002ef2282eae92f98) C:\Windows\system32\DRIVERS\termdd.sys
    2011/06/05 14:05:54.0967 5588 Tp4Track (9272164793d2e1ca0f831f6c472e8e08) C:\Windows\system32\DRIVERS\tp4track.sys
    2011/06/05 14:05:55.0030 5588 TPDIGIMN (017de0b5d88c099520f24a355636e19b) C:\Windows\system32\DRIVERS\ApsHM64.sys
    2011/06/05 14:05:55.0123 5588 TPM (270308efb59976157755c768b8544b5f) C:\Windows\system32\drivers\tpm.sys
    2011/06/05 14:05:55.0186 5588 TPPWRIF (2c067e01d6bbccc88b233b868e210907) C:\Windows\system32\drivers\Tppwr64v.sys
    2011/06/05 14:05:55.0233 5588 tssecsrv (9e5409cd17c8bef193aad498f3bc2cb8) C:\Windows\system32\DRIVERS\tssecsrv.sys
    2011/06/05 14:05:55.0311 5588 tunmp (89ec74a9e602d16a75a4170511029b3c) C:\Windows\system32\DRIVERS\tunmp.sys
    2011/06/05 14:05:55.0389 5588 tunnel (30a9b3f45ad081bffc3bcaa9c812b609) C:\Windows\system32\DRIVERS\tunnel.sys
    2011/06/05 14:05:55.0435 5588 tvtfilter (d66852a1de31fe48959841ed02fd1b92) C:\Windows\system32\DRIVERS\tvtfilter.sys
    2011/06/05 14:05:55.0482 5588 TVTI2C (b9aa92bae99d63897cb9de420a40e4e8) C:\Windows\system32\DRIVERS\Tvti2c.sys
    2011/06/05 14:05:55.0529 5588 tvtumon (03c3daa6c16dde7bbeae0e46d0315d84) C:\Windows\system32\DRIVERS\tvtumon.sys
    2011/06/05 14:05:55.0576 5588 uagp35 (fec266ef401966311744bd0f359f7f56) C:\Windows\system32\drivers\uagp35.sys
    2011/06/05 14:05:55.0623 5588 udfs (faf2640a2a76ed03d449e443194c4c34) C:\Windows\system32\DRIVERS\udfs.sys
    2011/06/05 14:05:55.0685 5588 uliagpkx (4ec9447ac3ab462647f60e547208ca00) C:\Windows\system32\drivers\uliagpkx.sys
    2011/06/05 14:05:55.0716 5588 uliahci (697f0446134cdc8f99e69306184fbbb4) C:\Windows\system32\drivers\uliahci.sys
    2011/06/05 14:05:55.0779 5588 UlSata (31707f09846056651ea2c37858f5ddb0) C:\Windows\system32\drivers\ulsata.sys
    2011/06/05 14:05:55.0810 5588 ulsata2 (85e5e43ed5b48c8376281bab519271b7) C:\Windows\system32\drivers\ulsata2.sys
    2011/06/05 14:05:55.0857 5588 umbus (46e9a994c4fed537dd951f60b86ad3f4) C:\Windows\system32\DRIVERS\umbus.sys
    2011/06/05 14:05:55.0935 5588 USBAAPL64 (54d4b48d443e7228bf64cf7cdc3118ac) C:\Windows\system32\Drivers\usbaapl64.sys
    2011/06/05 14:05:56.0013 5588 usbccgp (07e3498fc60834219d2356293da0fecc) C:\Windows\system32\DRIVERS\usbccgp.sys
    2011/06/05 14:05:56.0044 5588 usbcir (9247f7e0b65852c1f6631480984d6ed2) C:\Windows\system32\drivers\usbcir.sys
    2011/06/05 14:05:56.0106 5588 usbehci (827e44de934a736ea31e91d353eb126f) C:\Windows\system32\DRIVERS\usbehci.sys
    2011/06/05 14:05:56.0137 5588 usbhub (bb35cd80a2ececfadc73569b3d70c7d1) C:\Windows\system32\DRIVERS\usbhub.sys
    2011/06/05 14:05:56.0184 5588 usbohci (eba14ef0c07cec233f1529c698d0d154) C:\Windows\system32\drivers\usbohci.sys
    2011/06/05 14:05:56.0215 5588 usbprint (acfee697af477021bb3ec78c5431fed2) C:\Windows\system32\drivers\usbprint.sys
    2011/06/05 14:05:56.0247 5588 USBSTOR (b854c1558fca0c269a38663e8b59b581) C:\Windows\system32\DRIVERS\USBSTOR.SYS
    2011/06/05 14:05:56.0309 5588 usbuhci (b2872cbf9f47316abd0e0c74a1aba507) C:\Windows\system32\DRIVERS\usbuhci.sys
    2011/06/05 14:05:56.0356 5588 usbvideo (fc33099877790d51b0927b7039059855) C:\Windows\system32\Drivers\usbvideo.sys
    2011/06/05 14:05:56.0449 5588 vga (916b94bcf1e09873fff2d5fb11767bbc) C:\Windows\system32\DRIVERS\vgapnp.sys
    2011/06/05 14:05:56.0512 5588 VgaSave (b83ab16b51feda65dd81b8c59d114d63) C:\Windows\System32\drivers\vga.sys
    2011/06/05 14:05:56.0574 5588 viaide (e4522279e70facc314d0f3e35da2adab) C:\Windows\system32\drivers\viaide.sys
    2011/06/05 14:05:56.0668 5588 volmgr (2b7e885ed951519a12c450d24535dfca) C:\Windows\system32\drivers\volmgr.sys
    2011/06/05 14:05:56.0746 5588 volmgrx (cec5ac15277d75d9e5dec2e1c6eaf877) C:\Windows\system32\drivers\volmgrx.sys
    2011/06/05 14:05:56.0855 5588 volsnap (5280aada24ab36b01a84a6424c475c8d) C:\Windows\system32\drivers\volsnap.sys
    2011/06/05 14:05:56.0917 5588 vsmraid (a68f455ed2673835209318dd61bfbb0e) C:\Windows\system32\drivers\vsmraid.sys
    2011/06/05 14:05:56.0964 5588 WacomPen (fef8fe5923fead2cee4dfabfce3393a7) C:\Windows\system32\drivers\wacompen.sys
    2011/06/05 14:05:57.0011 5588 Wanarp (b8e7049622300d20ba6d8be0c47c0cfd) C:\Windows\system32\DRIVERS\wanarp.sys
    2011/06/05 14:05:57.0027 5588 Wanarpv6 (b8e7049622300d20ba6d8be0c47c0cfd) C:\Windows\system32\DRIVERS\wanarp.sys
    2011/06/05 14:05:57.0073 5588 Wd (0c17a0816f65b89e362e682ad5e7266e) C:\Windows\system32\drivers\wd.sys
    2011/06/05 14:05:57.0120 5588 Wdf01000 (d02e7e4567da1e7582fbf6a91144b0df) C:\Windows\system32\drivers\Wdf01000.sys
    2011/06/05 14:05:57.0229 5588 WimFltr (b14ef15bd757fa488f9c970eee9c0d35) C:\Windows\system32\DRIVERS\wimfltr.sys
    2011/06/05 14:05:57.0292 5588 winachsf (9e6c63f94d2c3d884a8936e448b1028b) C:\Windows\system32\DRIVERS\CAX_CNXT.sys
    2011/06/05 14:05:57.0401 5588 WmiAcpi (e18aebaaa5a773fe11aa2c70f65320f5) C:\Windows\system32\DRIVERS\wmiacpi.sys
    2011/06/05 14:05:57.0495 5588 WpdUsb (5e2401b3fc1089c90e081291357371a9) C:\Windows\system32\DRIVERS\wpdusb.sys
    2011/06/05 14:05:57.0526 5588 ws2ifsl (8a900348370e359b6bff6a550e4649e1) C:\Windows\system32\drivers\ws2ifsl.sys
    2011/06/05 14:05:57.0619 5588 WUDFRd (501a65252617b495c0f1832f908d54d8) C:\Windows\system32\DRIVERS\WUDFRd.sys
    2011/06/05 14:05:57.0666 5588 XAudio (f22e443518bc599d12888daf292a56d8) C:\Windows\system32\DRIVERS\xaudio64.sys
    2011/06/05 14:05:57.0760 5588 MBR (0x1B8) (5c616939100b85e558da92b899a0fc36) \Device\Harddisk0\DR0
    2011/06/05 14:05:57.0775 5588 ================================================== ==============================
    2011/06/05 14:05:57.0775 5588 Scan finished
    2011/06/05 14:05:57.0775 5588 ================================================== ==============================
    2011/06/05 14:05:57.0791 5772 Detected object count: 0
    2011/06/05 14:05:57.0791 5772 Actual detected object count: 0

  10. #10
    broni is offline Senior Member
    Save 20% on AVG Internet Security 2012 Suite!
    So should I select the "remove" option from Avira's message on C:\ComboFix\handle.cfxxe?
    No. This is legit Combofix file. Put it into Avira's exceptions.

    Which browser is getting redirected?

    Download OTL to your Desktop.

    • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    • Click the Scan All Users checkbox.
    • Under the Custom Scan box paste this in:



    netsvcs
    drivers32
    %SYSTEMDRIVE%\*.*
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\Fonts\*.exe
    %systemroot%\system32\spool\prtprocs\w32x86\*.*
    %systemroot%\REPAIR\*.bak1
    %systemroot%\REPAIR\*.ini
    %systemroot%\system32\*.jpg
    %systemroot%\*.jpg
    %systemroot%\*.png
    %systemroot%\*.scr
    %systemroot%\*._sy
    %APPDATA%\Adobe\Update\*.*
    %ALLUSERSPROFILE%\Favorites\*.*
    %APPDATA%\Microsoft\*.*
    %PROGRAMFILES%\*.*
    %APPDATA%\Update\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\System32\config\*.sav
    %PROGRAMFILES%\bak. /s
    %systemroot%\system32\bak. /s
    %ALLUSERSPROFILE%\Start Menu\*.lnk /x
    %systemroot%\system32\config\systemprofile\*.dat /x
    %systemroot%\*.config
    %systemroot%\system32\*.db
    %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x
    %USERPROFILE%\Desktop\*.exe
    %PROGRAMFILES%\Common Files\*.*
    %systemroot%\*.src
    %systemroot%\install\*.*
    %systemroot%\system32\DLL\*.*
    %systemroot%\system32\HelpFiles\*.*
    %systemroot%\system32\rundll\*.*
    %systemroot%\winn32\*.*
    %systemroot%\Java\*.*
    %systemroot%\system32\test\*.*
    %systemroot%\system32\Rundll32\*.*
    %systemroot%\AppPatch\Custom\*.*
    %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x
    %PROGRAMFILES%\PC-Doctor\Downloads\*.*
    %PROGRAMFILES%\Internet Explorer\*.tmp
    %PROGRAMFILES%\Internet Explorer\*.dat
    %USERPROFILE%\My Documents\*.exe
    %USERPROFILE%\*.exe
    %systemroot%\ADDINS\*.*
    %systemroot%\assembly\*.bak2
    %systemroot%\Config\*.*
    %systemroot%\REPAIR\*.bak2
    %systemroot%\SECURITY\Database\*.sdb /x
    %systemroot%\SYSTEM\*.bak2
    %systemroot%\Web\*.bak2
    %systemroot%\Driver Cache\*.*
    %PROGRAMFILES%\Mozilla Firefox\0*.exe
    %ProgramFiles%\Microsoft Common\*.*
    %ProgramFiles%\TinyProxy.
    %USERPROFILE%\Favorites\*.url /x
    %systemroot%\system32\*.bk
    %systemroot%\*.te
    %systemroot%\system32\system32\*.*
    %ALLUSERSPROFILE%\*.dat /x
    %systemroot%\system32\drivers\*.rmv
    dir /b "%systemroot%\system32\*.exe" | find /i " " /c
    dir /b "%systemroot%\*.exe" | find /i " " /c
    %PROGRAMFILES%\Microsoft\*.*
    %systemroot%\System32\Wbem\proquota.exe
    %PROGRAMFILES%\Mozilla Firefox\*.dat
    %USERPROFILE%\Cookies\*.txt /x
    %SystemRoot%\system32\fonts\*.*
    %systemroot%\system32\winlog\*.*
    %systemroot%\system32\Language\*.*
    %systemroot%\system32\Settings\*.*
    %systemroot%\system32\*.quo
    %SYSTEMROOT%\AppPatch\*.exe
    %SYSTEMROOT%\inf\*.exe
    %SYSTEMROOT%\Installer\*.exe
    %systemroot%\system32\config\*.bak2
    %systemroot%\system32\Computers\*.*
    %SystemRoot%\system32\Sound\*.*
    %SystemRoot%\system32\SpecialImg\*.*
    %SystemRoot%\system32\code\*.*
    %SystemRoot%\system32\draft\*.*
    %SystemRoot%\system32\MSSSys\*.*
    %ProgramFiles%\Javascript\*.*
    %systemroot%\pchealth\helpctr\System\*.exe /s
    %systemroot%\Web\*.exe
    %systemroot%\system32\msn\*.*
    %systemroot%\system32\*.tro
    %AppData%\Microsoft\Installer\msupdates\*.*
    %ProgramFiles%\Messenger\*.*
    %systemroot%\system32\systhem32\*.*
    %systemroot%\system\*.exe
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Win dows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs
    /md5start
    /md5stop


    • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
    • When the scan completes, it will open two notepad windows: OTL.txt and Extras.txt. These are saved in the same location as OTL.
    • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post them back here.

+ Reply to Thread
Page 1 of 7 1 2 3 4 5 6 7 LastLast